📦 Teedy

by Sismics

🔍 What is Teedy?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-54852

CRITICAL CVSS 9.8 Jan 29, 2025

This LDAP injection vulnerability in Teedy allows unauthenticated attackers to manipulate LDAP queries through the login form's username field. Attackers can create arbitrary accounts and perform pass...

CVE-2022-22114

CRITICAL CVSS 9.6 Jan 10, 2022

This is a reflected cross-site scripting (XSS) vulnerability in Teedy document management system that allows unauthenticated attackers to inject malicious scripts via search functionality. When victim...

CVE-2024-54851

HIGH CVSS 8.8 Jan 29, 2025

Teedy versions up to 1.12 lack CSRF protection, allowing attackers to trick authenticated users into performing unintended actions. This affects all Teedy instances running vulnerable versions, potent...

CVE-2025-22963

HIGH CVSS 7.5 Jan 13, 2025

This CSRF vulnerability in Teedy allows attackers to perform unauthorized administrative actions via a forged POST request to /api/user/admin. It affects all Teedy instances running versions through 1...

CVE-2025-11853

MEDIUM CVSS 6.3 Oct 16, 2025

CVE-2025-11853 is an improper access control vulnerability in Sismics Teedy's API endpoint that allows unauthorized access to files. Attackers can exploit this remotely to access sensitive documents w...