Testlink

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 29
    Known Exploited: 0
    6
    Critical Level Threats
    12
    High Level Threats
    10
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-70561

    TestLink 1.9.20 and prior Authenticated IDOR via attachmentdownload.php

    Last Modified: Aug 14, 2026
    Published: Aug 07, 2026

    CVE-2021-47760

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as a duplicate.

    Last Modified: Jan 22, 2026
    Published: Jan 15, 2026

    CVE-2024-46097

    TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section. When a new TestPlan is created, an ID with an incremental value is automatically generated. Using the edit function you can change the tplan_id parameter to another ID. The application does not carry out a check on the user's permissions maing it possible to recover the IDs of all the TestPlans (even the administrative ones) and modify them even with minimal privileges.

    Last Modified: Jul 10, 2025
    Published: Sep 27, 2024

    CVE-2024-42906

    TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file. When uploading a file, the XSS payload can be entered into the file name.

    Last Modified: Sep 05, 2024
    Published: Aug 26, 2024

    CVE-2023-50110

    TestLink through 1.9.20 allows type juggling for authentication bypass because === is not used.

    Last Modified: Nov 21, 2024
    Published: Dec 30, 2023
    Items Per Page