Tejimaya's vulnerability footprint centers on its OpenPNE social networking platform and OpenWebAPIPlugin, with the durable signal rooted in web-application input-handling and authentication weaknesses including XML external entity injection, improper authentication, input validation flaws, and cross-site scripting. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tejimaya over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-4334CRITICAL opWebAPIPlugin 0.5.1, 0.4.0, and 0.1.0: XXE Vulnerabilities | Feb 7, 2020 | 9.8 | 24 | NO | NO |
CVE-2013-4333CRITICAL OpenPNE 3 versions 3.8.7, 3.6.11, 3.4.21.1, 3.2.7.6, 3.0.8.5 has an External Entity Injection Vulnerability | Jan 24, 2020 | 9.1 | 23 | NO | NO |
CVE-2013-5350HIGH The "Remember me" feature in the opSecurityUser::getRememberLoginCookie function in lib/user/opSecurityUser.class.php in OpenPNE 3.6.13 before 3.6.13.1 and 3.8.9 before 3.8.9.1 doe | Jan 24, 2014 | 7.5 | 19 | NO | NO |
CVE-2010-1040MEDIUM The "IP address range limitation" function in OpenPNE 1.6 through 1.8, 2.0 through 2.8, 2.10 through 2.14, and 3.0 through 3.4, when mobile device support is enabled, allows remote | Mar 23, 2010 | 5.8 | 17 | NO | NO |
CVE-2013-2309MEDIUM Cross-site scripting (XSS) vulnerability in the management screen in OpenPNE 3.4.x before 3.4.21.1, 3.6.x before 3.6.9.1, and 3.8.x before 3.8.5.1 allows remote attackers to inject | Jun 17, 2013 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tejimaya.
Media articles that mention a CVE ID that affects a product developed by Tejimaya — matched by CVE ID, not by vendor name.