Tipask is a focused question-and-answer platform with a narrow product scope, with observed vulnerabilities centered on its core application. The durable signal reflects a supply-chain integrity weakness: download of code without integrity checks, which can expose the platform to trojanized dependencies or unsigned updates. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tipask over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41714MEDIUM In Tipask < 3.5.9, path parameters entered by the user are not validated when downloading attachments, a registered user can download arbitrary files on the Tipask server such as . | May 23, 2022 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tipask.
Media articles that mention a CVE ID that affects a product developed by Tipask — matched by CVE ID, not by vendor name.