Tongda2000 develops a modestly represented office automation and collaboration suite, primarily centered on its Office Anywhere product line, that has accumulated a durable concentration of critical-severity vulnerabilities. The vendor's exposure skews strongly toward critical outcomes across its applications, reflecting a pattern of recurring input-handling and access-control weaknesses including SQL injection, cross-site scripting, improper authorization, and resource-exhaustion conditions that are typical of web-facing business software with insufficient input validation and privilege-boundary enforcement. These weakness classes recur across its core Office Anywhere offerings and represent fundamental flaws in how the software sanitizes user-supplied data and enforces role-based access, making each disclosure a potential high-impact risk for organizations relying on the platform. Defenders should treat this vendor's security advisories as urgent and apply patches broadly within affected deployments; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tongda2000 over time
Signals from CVEs in this vendor scope (59 CVEs).
59 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4166CRITICAL A vulnerability has been found in Tongda OA and classified as critical. This vulnerability affects unknown code of the file general/system/seal_manage/dianju/delete_log.php. The ma | Aug 5, 2023 | 9.8 | 35 | NO | NO |
CVE-2023-4165CRITICAL A vulnerability, which was classified as critical, was found in Tongda OA. This affects an unknown part of the file general/system/seal_manage/iweboffice/delete_seal.php. The manip | Aug 5, 2023 | 9.8 | 35 | NO | NO |
CVE-2022-25406CRITICAL Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete_query.php via the DELETE_STR parameter. | Feb 24, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-25405CRITICAL Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in change_box.php via the DELETE_STR parameter. | Feb 24, 2022 | 9.8 | 31 | NO | NO |
CVE-2024-10618CRITICAL A vulnerability, which was classified as critical, has been found in Tongda OA 2017 up to 11.10. This issue affects some unknown processing of the file /pda/reportshop/record_detai | Nov 1, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-10600CRITICAL A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.6. Affected is an unknown function of the file pda/appcenter/submenu.php. The manipulation o | Oct 31, 2024 | 9.8 | 30 | NO | NO |
CVE-2023-7023CRITICAL A vulnerability was found in Tongda OA 2017 up to 11.9. It has been rated as critical. Affected by this issue is some unknown functionality of the file general/vehicle/query/delete | Dec 21, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-5682CRITICAL A vulnerability has been found in Tongda OA 2017 and classified as critical. This vulnerability affects unknown code of the file general/hr/training/record/delete.php. The manipula | Oct 20, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-5019CRITICAL A vulnerability classified as critical was found in Tongda OA. This vulnerability affects unknown code of the file general/hr/manage/staff_reinstatement/delete.php. The manipulatio | Sep 17, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-2738CRITICAL A vulnerability classified as critical has been found in Tongda OA 11.10. This affects the function actionGetdata of the file GatewayController.php. The manipulation leads to unres | May 16, 2023 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (59 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tongda2000.
Media articles that mention a CVE ID that affects a product developed by Tongda2000 — matched by CVE ID, not by vendor name.