Tunasite operates a focused advertising platform, with a vulnerability profile concentrated in path-traversal and unrestricted file-upload weaknesses in its Adning advertising product. These issues reflect common risks in user-facing content and file-handling systems; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tunasite over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-36728CRITICAL The Adning Advertising plugin for WordPress is vulnerable to file deletion via path traversal in versions up to, and including, 1.5.5. This allows unauthenticated attackers to dele | Jun 7, 2023 | 9.8 | 43 | NO | YES |
CVE-2020-36705CRITICAL The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _ning_upload_image function in versions up to, and in | Jun 7, 2023 | 9.8 | 42 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tunasite.
Media articles that mention a CVE ID that affects a product developed by Tunasite — matched by CVE ID, not by vendor name.