Tendenci is a modestly represented, open-source content management system positioned as a platform for association and nonprofit websites, where its vulnerability exposure concentrates in web-application input handling and data processing. The vendor's disclosures skew strongly toward critical-severity outcomes and recur through weakness classes including cross-site scripting, unsafe deserialization, code injection, and CSV formula injection—characteristic of CMS frameworks that process untrusted user input and administrative uploads without sufficient sanitization. Defenders deploying Tendenci should prioritize patching for its core CMS product and maintain strict input validation policies; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tendenci over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-36962CRITICAL Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers to inject malicious formulas during export. Attackers can sub | Jan 28, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-23946MEDIUM Tendenci is an open source content management system built for non-profits, associations and cause-based sites. Versions 15.3.11 and below include a critical deserialization vulner | Jan 22, 2026 | 6.8 | 26 | NO | NO |
CVE-2020-14942CRITICAL Tendenci 12.0.10 allows unrestricted deserialization in apps\helpdesk\views\staff.py. | Jun 21, 2020 | 9.8 | 24 | NO | NO |
CVE-2025-70960MEDIUM A stored cross-site scripting (XSS) vulnerability in the Forums module of Tendenci CMS v15.3.7 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted pay | Feb 2, 2026 | 5.4 | 18 | NO | NO |
CVE-2025-70959MEDIUM A stored cross-site scripting (XSS) vulnerability in the Jobs module of Tendenci CMS v15.3.7 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted paylo | Feb 2, 2026 | 5.4 | 18 | NO | NO |
CVE-2008-0793MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in search.asp in Tendenci CMS allow remote attackers to inject arbitrary web script or HTML via the (1) category, (2) searchtext | Feb 15, 2008 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tendenci.
Media articles that mention a CVE ID that affects a product developed by Tendenci — matched by CVE ID, not by vendor name.