Total
2 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2020-36962 | 1 Tendenci | 1 Tendenci | 2026-02-02 | N/A | 9.8 CRITICAL |
| Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers to inject malicious formulas during export. Attackers can submit crafted payloads like '=10+20+cmd|' /C calc'!A0' in the message field to trigger arbitrary command execution when the CSV is opened in spreadsheet applications. | |||||
| CVE-2020-14942 | 1 Tendenci | 1 Tendenci | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
| Tendenci 12.0.10 allows unrestricted deserialization in apps\helpdesk\views\staff.py. | |||||
