Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Tine20

First CVE: Sep 30, 2017Active for: 9 yearsTotal CVEs: 4

Tine20 is a groupware and collaboration platform with a focused product footprint centered on its core Tine 2.0 application, which serves as a calendar, contact, and task-management system for organizations seeking open-source alternatives to commercial suites. Its observed vulnerability exposure clusters around cross-site scripting weaknesses inherent to web-based input handling, reflecting the attack surface typical of server-side web applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
4
Total CVEs
More Total CVEs than 79% of tracked vendors
4.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
5.4
Avg CVSS Score
Higher Avg CVSS Score than 16% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Tine20 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 30, 2017
8 years ago
Most Recent CVE
Nov 17, 2017
3,171 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (4 CVEs).

4 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-14923MEDIUM
Stored XSS vulnerability via IMG element at "Leadname" of CRM in Tine 2.0 Community Edition before 2017.08.4 allows an authenticated user to inject JavaScript, which is mishandled
Sep 30, 20175.419NONO
CVE-2017-14922MEDIUM
Stored XSS vulnerability via IMG element at "History" of Profile, Calendar, Tasks, and CRM in Tine 2.0 Community Edition before 2017.08.4 allows an authenticated user to inject Jav
Sep 30, 20175.419NONO
CVE-2017-14921MEDIUM
Stored XSS vulnerability via IMG element at "Filename" of Filemanager in Tine 2.0 Community Edition before 2017.08.4 allows an authenticated user to inject JavaScript, which is mis
Sep 30, 20175.419NONO
CVE-2017-1000164MEDIUM
Tine 2.0 version 2017.02.4 is vulnerable to XSS in the Addressbook resulting code execution and privilege escalation
Nov 17, 20175.418NONO
View all 4 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products4 CVEs
100%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network4 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required4 (100.0%)
Privileges Required
Low4 (100.0%)
High0 (0.0%)
None0 (0.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (4 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Tine20.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Tine20 — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Tine20's Products

View all 1 CNAs →

Top CWEs