Tine20 is a groupware and collaboration platform with a focused product footprint centered on its core Tine 2.0 application, which serves as a calendar, contact, and task-management system for organizations seeking open-source alternatives to commercial suites. Its observed vulnerability exposure clusters around cross-site scripting weaknesses inherent to web-based input handling, reflecting the attack surface typical of server-side web applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tine20 over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14923MEDIUM Stored XSS vulnerability via IMG element at "Leadname" of CRM in Tine 2.0 Community Edition before 2017.08.4 allows an authenticated user to inject JavaScript, which is mishandled | Sep 30, 2017 | 5.4 | 19 | NO | NO |
CVE-2017-14922MEDIUM Stored XSS vulnerability via IMG element at "History" of Profile, Calendar, Tasks, and CRM in Tine 2.0 Community Edition before 2017.08.4 allows an authenticated user to inject Jav | Sep 30, 2017 | 5.4 | 19 | NO | NO |
CVE-2017-14921MEDIUM Stored XSS vulnerability via IMG element at "Filename" of Filemanager in Tine 2.0 Community Edition before 2017.08.4 allows an authenticated user to inject JavaScript, which is mis | Sep 30, 2017 | 5.4 | 19 | NO | NO |
CVE-2017-1000164MEDIUM Tine 2.0 version 2017.02.4 is vulnerable to XSS in the Addressbook resulting code execution and privilege escalation | Nov 17, 2017 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tine20.
Media articles that mention a CVE ID that affects a product developed by Tine20 — matched by CVE ID, not by vendor name.