Tcexam
Tecnick · 23 CVEs
Tecnick TCExam XML Export tce_xml_users.php F_xml_export_users cross site scripting
Mar 15, 2026
Tecnick TCExam Group tce_edit_group.php cross site scripting
Mar 15, 2026
Tecnick – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Apr 22, 2025
Tecnick - Multiple XSS (CWE-79)
Apr 22, 2025
Tecnick TCExam – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Dec 30, 2024
Tecnick TCExam – Multiple CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Dec 30, 2024
Missing authorisation in TCExam
Jan 11, 2024
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4. The paths provided in the f, d, and dir para…
Aug 5, 2021
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. The paths provided in the f, d, and dir para…
Aug 5, 2021
When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the…
Jul 29, 2021
An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1. If a password reset request was made for…
Jul 29, 2021
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.p…
Jul 29, 2021
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php wi…
Jul 29, 2021
Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross…
May 7, 2020
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-s…
May 7, 2020
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-s…
May 7, 2020
Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross…
May 7, 2020
Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricki…
May 7, 2020
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-s…
May 7, 2020
Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metada…
May 7, 2020
Relative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary file…
May 7, 2020
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-s…
May 7, 2020
TCExam before 14.1.2 has XSS via an ff_ or xl_ field.
Jul 7, 2018
Multiple cross-site scripting (XSS) vulnerabilities in admin/code/tce_select_users_popup.php in Nicola Asuni TCExam bef…
Nov 23, 2012
Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with lev…
Nov 23, 2012
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-4169 | Tecnick TCExam XML Export tce_xml_users.php F_xml_export_users cross site scripting | MEDIUM | 0.35% | Mar 15, 2026 |
| CVE-2026-4168 | Tecnick TCExam Group tce_edit_group.php cross site scripting | MEDIUM | 0.35% | Mar 15, 2026 |
| CVE-2025-23176 | Tecnick – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | HIGH | 0.48% | Apr 22, 2025 |
| CVE-2025-23175 | Tecnick - Multiple XSS (CWE-79) | MEDIUM | 0.24% | Apr 22, 2025 |
| CVE-2024-47926 | Tecnick TCExam – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | CRITICAL | 0.57% | Dec 30, 2024 |
| CVE-2024-47925 | Tecnick TCExam – Multiple CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | HIGH | 0.50% | Dec 30, 2024 |
| CVE-2023-6554 | Missing authorisation in TCExam | MEDIUM | 0.58% | Jan 11, 2024 |
| CVE-2021-20116 | A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4. The paths provided in the f, d, and dir parameters in tce_select_mediafile.php were… | MEDIUM | 0.94% | Aug 5, 2021 |
| CVE-2021-20115 | A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. The paths provided in the f, d, and dir parameters in tce_filemanager.php were not p… | MEDIUM | 0.95% | Aug 5, 2021 |
| CVE-2021-20114 | When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which include… | HIGH | 5.97% | Jul 29, 2021 |
| CVE-2021-20113 | An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1. If a password reset request was made for an email address that was not registere… | MEDIUM | 1.30% | Jul 29, 2021 |
| CVE-2021-20112 | A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.php with a filename beggining with a peri… | MEDIUM | 0.63% | Jul 29, 2021 |
| CVE-2021-20111 | A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php with a filename beggining with a period wi… | MEDIUM | 0.61% | Jul 29, 2021 |
| CVE-2020-5750 | Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks via the se… | MEDIUM | 1.14% | May 7, 2020 |
| CVE-2020-5749 | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating… | MEDIUM | 0.67% | May 7, 2020 |
| CVE-2020-5751 | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating… | MEDIUM | 0.67% | May 7, 2020 |
| CVE-2020-5748 | Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks via the se… | MEDIUM | 1.13% | May 7, 2020 |
| CVE-2020-5745 | Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a craf… | HIGH | 0.83% | May 7, 2020 |
| CVE-2020-5746 | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating… | MEDIUM | 0.67% | May 7, 2020 |
| CVE-2020-5743 | Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadata for which they don't have permission. | MEDIUM | 0.82% | May 7, 2020 |
| CVE-2020-5744 | Relative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary files on disk. | MEDIUM | 1.41% | May 7, 2020 |
| CVE-2020-5747 | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating… | MEDIUM | 0.67% | May 7, 2020 |
| CVE-2018-13422 | TCExam before 14.1.2 has XSS via an ff_ or xl_ field. | MEDIUM | 0.82% | Jul 7, 2018 |
| CVE-2012-4602 | Multiple cross-site scripting (XSS) vulnerabilities in admin/code/tce_select_users_popup.php in Nicola Asuni TCExam before 11.3.009 allow remote attackers to i… | MEDIUM | 1.79% | Nov 23, 2012 |
| CVE-2012-4601 | Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with level 5 or greater permissions to execute a… | MEDIUM | 1.56% | Nov 23, 2012 |
Showing 1 to 23 of 23 CVEs