Tdiary is a niche blogging and content-management platform with a narrowly focused vulnerability profile centered on its single product. The observed weaknesses cluster around input-handling and output-encoding issues, including improper input validation and cross-site scripting vulnerabilities typical of web-facing publishing applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tdiary over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-6852MEDIUM Eval injection vulnerability in tDiary 2.0.3 and 2.1.4.200 61127 allows remote authenticated users to execute arbitrary Ruby code via unspecified vectors, possibly related to incor | Dec 31, 2006 | 6.0 | 17 | NO | NO |
CVE-2010-0726MEDIUM Cross-site scripting (XSS) vulnerability in the tb-send.rb (TrackBack transmission) plugin in tDiary 2.2.2 and earlier allows remote attackers to inject arbitrary web script or HTM | Mar 2, 2010 | 4.3 | 16 | NO | NO |
CVE-2005-2411MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in tDiary 2.1.1, and tDiary 2.0.1 and earlier, allows remote attackers to conduct actions as another user, and execute commands on t | Aug 1, 2005 | 5.1 | 15 | NO | NO |
CVE-2006-6174MEDIUM Cross-site scripting (XSS) vulnerability in tDiary before 2.0.3 and 2.1.x before 2.1.4.20061126 allows remote attackers to inject arbitrary web script or HTML via the conf paramete | Nov 30, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tdiary.
Media articles that mention a CVE ID that affects a product developed by Tdiary — matched by CVE ID, not by vendor name.