Terminalfour develops a web content management and digital experience platform widely deployed in higher education and enterprise settings, where its core products include the content management system and associated form-handling components. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through application-layer weakness classes including cross-site scripting, improper authorization, and information-disclosure patterns typical of web platforms handling user input and access control. Defenders should treat this vendor's advisories as priority updates for internet-facing content and form infrastructure; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Terminalfour over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-58386CRITICAL In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper server-side authorization checks. A Power User can intercept and | Dec 2, 2025 | 9.8 | 30 | NO | NO |
CVE-2022-30770MEDIUM Terminalfour versions 8.3.7, 8.3.x versions prior to version 8.3.8 and r 8.2.x versions prior to version 8.2.18.5 or 8.2.18.2.1 are vulnerable to (XSS) vulnerability that could be | May 16, 2022 | 6.1 | 22 | NO | NO |
CVE-2023-29484MEDIUM In Terminalfour before 8.3.16, misconfigured LDAP users are able to login with an invalid password. | Oct 16, 2023 | 6.5 | 19 | NO | NO |
CVE-2023-23591MEDIUM The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed | Apr 12, 2023 | 4.9 | 19 | NO | NO |
CVE-2024-22220MEDIUM An issue was discovered in Terminalfour 7.4 through 7.4.0004 QP3 and 8 through 8.3.19, and Formbank through 2.1.10-FINAL. Unauthenticated Stored Cross-Site Scripting can occur, wit | Feb 21, 2024 | 6.3 | 18 | NO | NO |
CVE-2024-22217MEDIUM A Server-Side Request Forgery (SSRF) vulnerability in Terminalfour before 8.3.19 allows authenticated users to use specific features to access internal services including sensitive | Aug 15, 2024 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Terminalfour.
Media articles that mention a CVE ID that affects a product developed by Terminalfour — matched by CVE ID, not by vendor name.