Tendenci

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 6
    Known Exploited: 0
    2
    Critical Level Threats
    0
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-70960

    A stored cross-site scripting (XSS) vulnerability in the Forums module of Tendenci CMS v15.3.7 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.

    Last Modified: Feb 11, 2026
    Published: Feb 02, 2026

    CVE-2025-70959

    A stored cross-site scripting (XSS) vulnerability in the Jobs module of Tendenci CMS v15.3.7 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.

    Last Modified: Feb 11, 2026
    Published: Feb 02, 2026

    CVE-2020-36962

    Tendenci 12.3.1 - CSV/ Formula Injection

    Last Modified: Mar 05, 2026
    Published: Jan 28, 2026

    CVE-2026-23946

    Tendenci has Authenticated Remote Code Execution via Pickle Deserialization

    Last Modified: Apr 18, 2026
    Published: Jan 22, 2026

    CVE-2020-14942

    Tendenci 12.0.10 allows unrestricted deserialization in apps\helpdesk\views\staff.py.

    Last Modified: Nov 21, 2024
    Published: Jun 21, 2020
    Items Per Page