Teamst's vulnerability profile concentrates in TestLink, a test-management application, where the durable signal centers on application-layer input-handling and session-management issues including cross-site scripting, cross-site request forgery, and SQL injection. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Teamst over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-2275MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in TestLink 1.9.3 and earlier allow remote attackers to hijack the authentication of users for requests that add, delete, | Sep 15, 2012 | 6.8 | 30 | NO | YES |
CVE-2009-4238MEDIUM Multiple SQL injection vulnerabilities in TestLink before 1.8.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the Test Case ID field to lib/general/nav | Dec 10, 2009 | 6.5 | 25 | NO | YES |
Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the req parameter to login.php, a | Dec 10, 2009 | 3.5 | 20 | NO | YES |
CVE-2008-5807MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.8 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) Testproject Names and (2) Testp | Dec 31, 2008 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Teamst.
Media articles that mention a CVE ID that affects a product developed by Teamst — matched by CVE ID, not by vendor name.