Teamworktec operates a modest portfolio of web and productivity applications including Job Links, Photo Fusion, and TicketPlus, with a durable exposure pattern centered on unrestricted file-upload handling. The recurrence of dangerous file-type validation weaknesses across these products reflects a common vulnerability class in user-facing web applications where insufficient controls on uploaded content create a foothold for malicious payloads. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Teamworktec over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14840HIGH TeamWork TicketPlus allows Arbitrary File Upload in updateProfile. | Sep 28, 2017 | 8.8 | 37 | NO | YES |
CVE-2017-14839HIGH TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover. | Sep 28, 2017 | 8.8 | 37 | NO | YES |
CVE-2017-14838HIGH TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange. | Sep 28, 2017 | 8.8 | 37 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Teamworktec.
Media articles that mention a CVE ID that affects a product developed by Teamworktec — matched by CVE ID, not by vendor name.