Tadtools ProjectCVEs & Vulnerabilities
3 CVEs affecting Tadtools Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
3 CVEs→ All vendors
Most Affected Products
tadtools 3
CVE-2021-41975CRITICAL
TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to delete arbitrary files in the system without logging in.
8 Oct 2021
9.1
CVSS
CVE-2021-41566CRITICAL
The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arbitrary code without logging in.
8 Oct 2021
9.8
CVSS
CVE-2021-41565MEDIUM
TadTools special page parameter does not properly restrict the input of specific characters, thus remote attackers can inject JavaScript syntax without logging in, and further perform reflective XSS attacks.
8 Oct 2021
6.1
CVSS
← PrevPage 1 / 1Next →