taigaio Vulnerabilities and Affected Products
Vulnerabilities associated with taiga_front.
Products
Clear product- taiga-back2 vulnerabilities
- taiga_front2 vulnerabilities
- taiga-front1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-53555HIGH | A CSV injection vulnerability in Taiga v6.8.1 allows attackers to execute arbitrary code via uploading a crafted CSV file. CWE-1236Nov 26, 2024 | CVSS8.8v3.1 | EPSS0.675% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-53554HIGH | A Client-Side Template Injection (CSTI) vulnerability in the component /project/new/scrum of Taiga v 8.6.1 allows remote attackers to execute arbitrary code by injecting a malicious payload within the new project details. CWE-94Nov 25, 2024 | CVSS8.0v3.1 | EPSS0.708% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |