TortoiseSVN is a Windows shell integration client for the Subversion version-control system, presenting a focused, developer-facing attack surface. The vulnerability signals center on path-traversal and file-access control issues, reflecting the file-system operations inherent to a working-copy management tool; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tortoisesvn over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14422HIGH An issue was discovered in in TortoiseSVN 1.12.1. The Tsvncmd: URI handler allows a customised diff operation on Excel workbooks, which could be used to open remote workbooks witho | Aug 15, 2019 | 8.8 | 45 | NO | YES |
CVE-2007-3846MEDIUM Directory traversal vulnerability in Subversion before 1.4.5, as used by TortoiseSVN before 1.4.5 and possibly other products, when run on Windows-based systems, allows remote auth | Aug 28, 2007 | 6.0 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tortoisesvn.
Media articles that mention a CVE ID that affects a product developed by Tortoisesvn — matched by CVE ID, not by vendor name.