Tilde develops a content-management system product whose vulnerability profile centers on web-application input-handling weaknesses, specifically SQL injection, cross-site scripting, and sensitive-information exposure. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tilde over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-6159HIGH SQL injection vulnerability in index.php in Tilde CMS 4.x and earlier allows remote attackers to execute arbitrary SQL commands via the aarstal parameter in a yeardetail action, a | Nov 29, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-6160MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Tilde CMS 4.x and earlier allows remote attackers to inject arbitrary web script or HTML via the aarstal parameter in a yea | Nov 29, 2007 | 4.3 | 21 | NO | YES |
CVE-2006-1500HIGH SQL injection vulnerability in index.php in Tilde CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Mar 30, 2006 | 7.5 | 19 | NO | NO |
CVE-2007-6161MEDIUM index.php in Tilde CMS 4.x and earlier allows remote attackers to obtain sensitive information via a certain search parameter value in a search action, which reveals the path. | Nov 29, 2007 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tilde.
Media articles that mention a CVE ID that affects a product developed by Tilde — matched by CVE ID, not by vendor name.