Tecnick maintains a modestly sized portfolio of web-facing assessment and document-generation tools, notably TCExam, AIOCP, and TCPDF, that occupy a niche but meaningful presence in the vulnerability landscape. The vendor's disclosures cluster around application-layer input-handling and access-control weaknesses including cross-site scripting, SQL injection, code injection, and cross-site request forgery, alongside authorization-bypass conditions arising from user-controlled keys—patterns typical of web applications with evolving security maturity. Vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting the relative accessibility of web-application attack surfaces. Defenders should monitor this vendor's releases closely when these products are deployed in assessment or document-processing roles and prioritize input-validation and access-control remediations; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tecnick over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-17057CRITICAL An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper. | Sep 14, 2018 | 9.8 | 52 | NO | YES |
CVE-2021-20114HIGH When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database | Jul 30, 2021 | 7.5 | 37 | NO | YES |
CVE-2010-2153MEDIUM Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 allows remote attackers to execute arbitrary code by uploading | Jun 3, 2010 | 6.8 | 33 | NO | YES |
CVE-2009-3220HIGH PHP remote file inclusion vulnerability in cp_html2txt.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute arbitrary PHP code via a URL in the page p | Sep 16, 2009 | 7.5 | 33 | NO | YES |
CVE-2012-4237MEDIUM Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to execute arbitrary SQL commands via the subj | Aug 20, 2012 | 6.8 | 31 | NO | YES |
CVE-2009-4747HIGH PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute arbitrary PHP code via | Mar 26, 2010 | 7.5 | 29 | NO | YES |
CVE-2023-6554MEDIUM When access to the "admin" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it is possible for any user to download protected information l | Jan 11, 2024 | 6.5 | 21 | NO | NO |
CVE-2021-20116MEDIUM A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4. The paths provided in the f, d, and dir parameters in tce_select_mediafile.php were not properly validate | Aug 5, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-20115MEDIUM A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. The paths provided in the f, d, and dir parameters in tce_filemanager.php were not properly validated and | Aug 5, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-20113MEDIUM An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1. If a password reset request was made for an email address that was not registered with a user then we | Jul 30, 2021 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tecnick.
Media articles that mention a CVE ID that affects a product developed by Tecnick — matched by CVE ID, not by vendor name.