VendorsSismicsteedyany version
Vulnerabilities

Sismics Teedy any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2024-54852
When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user input, an unauthenticated attacker is then able to perform various malicious actions, such as creating arbitrary accounts and spraying passwords.
Published 2025-01-29 · Analyzed
9.8EPSS 0.008
CVE-2022-22114
Teedy - Reflected Cross-Site Scripting (XSS) in the Search Functionality
Published 2022-01-10 · Modified
9.6EPSS 0.013
CVE-2022-22115
Teedy - Stored Cross-Site Scripting (XSS) in Tag Name
Published 2022-01-10 · Modified
9.0EPSS 0.010
CVE-2024-54851
Teedy <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF), due to the lack of CSRF protection.
Published 2025-01-29 · Analyzed
8.8EPSS 0.003
CVE-2025-11853
Sismics Teedy API Endpoint file access control
Published 2025-10-16 · Modified
8.1EPSS 0.005
CVE-2025-22963
Teedy through 1.11 allows CSRF for account takeover via POST /api/user/admin.
Published 2025-01-13 · Analyzed
7.5EPSS 0.003