Tcexam

Tecnick · 23 CVEs

CVE-2026-4169
MEDIUM

Tecnick TCExam XML Export tce_xml_users.php F_xml_export_users cross site scripting

Mar 15, 2026

CVE-2026-4168
MEDIUM

Tecnick TCExam Group tce_edit_group.php cross site scripting

Mar 15, 2026

CVE-2025-23176
HIGH

Tecnick – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Apr 22, 2025

CVE-2025-23175
MEDIUM

Tecnick - Multiple XSS (CWE-79)

Apr 22, 2025

CVE-2024-47926
CRITICAL

Tecnick TCExam – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Dec 30, 2024

CVE-2024-47925
HIGH

Tecnick TCExam – Multiple CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Dec 30, 2024

CVE-2023-6554
MEDIUM

Missing authorisation in TCExam

Jan 11, 2024

CVE-2021-20116
MEDIUM

A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4. The paths provided in the f, d, and dir para…

Aug 5, 2021

CVE-2021-20115
MEDIUM

A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. The paths provided in the f, d, and dir para…

Aug 5, 2021

CVE-2021-20114
HIGH

When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the…

Jul 29, 2021

CVE-2021-20113
MEDIUM

An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1. If a password reset request was made for…

Jul 29, 2021

CVE-2021-20112
MEDIUM

A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.p…

Jul 29, 2021

CVE-2021-20111
MEDIUM

A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php wi…

Jul 29, 2021

CVE-2020-5750
MEDIUM

Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross…

May 7, 2020

CVE-2020-5749
MEDIUM

Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-s…

May 7, 2020

CVE-2020-5751
MEDIUM

Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-s…

May 7, 2020

CVE-2020-5748
MEDIUM

Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross…

May 7, 2020

CVE-2020-5745
HIGH

Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricki…

May 7, 2020

CVE-2020-5746
MEDIUM

Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-s…

May 7, 2020

CVE-2020-5743
MEDIUM

Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metada…

May 7, 2020

CVE-2020-5744
MEDIUM

Relative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary file…

May 7, 2020

CVE-2020-5747
MEDIUM

Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-s…

May 7, 2020

CVE-2018-13422
MEDIUM

TCExam before 14.1.2 has XSS via an ff_ or xl_ field.

Jul 7, 2018

CVE-2012-4602
MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in admin/code/tce_select_users_popup.php in Nicola Asuni TCExam bef…

Nov 23, 2012

CVE-2012-4601
MEDIUM

Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with lev…

Nov 23, 2012

Showing 1 to 23 of 23 CVEs