testlink CVE Vulnerabilities & Metrics

Focus on testlink vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About testlink Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with testlink. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total testlink CVEs: 20
Earliest CVE date: 14 Aug 2014, 14:55 UTC
Latest CVE date: 26 Aug 2024, 20:15 UTC

Latest CVE reference: CVE-2024-42906

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical testlink CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.69

Max CVSS: 9.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 6
4.0-6.9 13
7.0-8.9 5
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS testlink CVEs

These are the five CVEs with the highest CVSS scores for testlink, sorted by severity first and recency.

All CVEs for testlink

CVE-2024-42906 testlink vulnerability CVSS: 0 26 Aug 2024, 20:15 UTC

TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file. When uploading a file, the XSS payload can be entered into the file name.

CVE-2023-50110 testlink vulnerability CVSS: 0 30 Dec 2023, 17:15 UTC

TestLink through 1.9.20 allows type juggling for authentication bypass because === is not used.

CVE-2022-35196 testlink vulnerability CVSS: 0 20 Sep 2022, 16:15 UTC

TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.

CVE-2022-35194 testlink vulnerability CVSS: 0 16 Sep 2022, 22:15 UTC

TestLink v1.9.20 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /lib/inventory/inventoryView.php.

CVE-2022-35195 testlink vulnerability CVSS: 0 16 Sep 2022, 16:15 UTC

TestLink 1.9.20 Raijin was discovered to contain a broken access control vulnerability at /lib/attachments/attachmentdownload.php

CVE-2022-35193 testlink vulnerability CVSS: 0 16 Sep 2022, 16:15 UTC

TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php.

CVE-2020-12274 testlink vulnerability CVSS: 7.5 27 Apr 2020, 13:15 UTC

In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on client input and is not constrained to lib/cfields/cfieldsView.php at the web site associated with the session.

CVE-2020-12273 testlink vulnerability CVSS: 5.0 27 Apr 2020, 13:15 UTC

In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials.

CVE-2020-8639 testlink vulnerability CVSS: 6.5 03 Apr 2020, 19:15 UTC

An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. This allows an authenticated attacker to upload a malicious file (containing PHP code to execute operating system commands) to a publicly accessible directory of the application.

CVE-2020-8638 testlink vulnerability CVSS: 7.5 03 Apr 2020, 19:15 UTC

A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency parameter.

CVE-2020-8637 testlink vulnerability CVSS: 7.5 03 Apr 2020, 19:15 UTC

A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id parameter.

CVE-2019-20107 testlink vulnerability CVSS: 6.5 05 Mar 2020, 13:15 UTC

Multiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary SQL commands via the (1) tproject_id parameter to keywordsView.php; the (2) req_spec_id parameter to reqSpecCompareRevisions.php; the (3) requirement_id parameter to reqCompareVersions.php; the (4) build_id parameter to planUpdateTC.php; the (5) tplan_id parameter to newest_tcversions.php; the (6) tplan_id parameter to tcCreatedPerUserGUI.php; the (7) tcase_id parameter to tcAssign2Tplan.php; or the (8) testcase_id parameter to tcCompareVersions.php. Authentication is often easy to achieve: a guest account, that can execute this attack, can be created by anyone in the default configuration.

CVE-2020-8841 testlink vulnerability CVSS: 6.5 10 Feb 2020, 21:56 UTC

An issue was discovered in TestLink 1.9.19. The relation_type parameter of the lib/requirements/reqSearch.php endpoint is vulnerable to authenticated SQL Injection.

CVE-2019-20381 testlink vulnerability CVSS: 4.3 20 Jan 2020, 06:15 UTC

TestLink before 1.9.20 allows XSS via non-lowercase javascript: in the index.php reqURI parameter. NOTE: this issue exists because of an incomplete fix for CVE-2019-19491.

CVE-2019-19491 testlink vulnerability CVSS: 4.3 02 Dec 2019, 02:15 UTC

TestLink 1.9.19 has XSS via the lib/testcases/archiveData.php edit parameter, the index.php reqURI parameter, or the URI in a lib/testcases/tcEdit.php?doAction=doDeleteStep request.

CVE-2019-14471 testlink vulnerability CVSS: 4.3 01 Aug 2019, 15:15 UTC

TestLink 1.9.19 has XSS via the error.php message parameter.

CVE-2018-7668 testlink vulnerability CVSS: 5.0 05 Mar 2018, 07:29 UTC

TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachments/attachmentdownload.php.

CVE-2018-7466 testlink vulnerability CVSS: 6.0 25 Feb 2018, 07:29 UTC

install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGIN NAMES data during installation to provide a long, crafted value.

CVE-2015-7391 testlink vulnerability CVSS: 4.3 26 Sep 2017, 15:29 UTC

Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.9.14 allow remote attackers to inject arbitrary web script or HTML via the (1) selected_end_date or (2) selected_start_date parameter to lib/results/tcCreatedPerUserOnTestProject.php; the (3) containerType parameter to lib/testcases/containerEdit.php; the (4) filter_tc_id or (5) filter_testcase_name parameter to lib/testcases/listTestCases.php; the (6) useRecursion parameter to lib/testcases/tcImport.php; the (7) targetTestCase or (8) created_by parameter to lib/testcases/tcSearch.php; or the (9) HTTP Referer header to third_party/user_contribution/fakeRemoteExecServer/client4fakeXMLRPCTestRunner.php.

CVE-2015-7390 testlink vulnerability CVSS: 7.5 26 Sep 2017, 15:29 UTC

SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to lnl.php.

CVE-2014-8082 testlink vulnerability CVSS: 5.0 31 Oct 2014, 14:55 UTC

lib/functions/database.class.php in TestLink before 1.9.13 allows remote attackers to obtain sensitive information via unspecified vectors, which reveals the installation path in an error message.

CVE-2014-8081 testlink vulnerability CVSS: 7.5 31 Oct 2014, 14:55 UTC

lib/execute/execSetResults.php in TestLink before 1.9.13 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the filter_result_result parameter.

CVE-2014-5308 testlink vulnerability CVSS: 9.0 08 Oct 2014, 17:55 UTC

Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL commands via the (1) name parameter in a Search action to lib/project/projectView.php or (2) id parameter to lib/events/eventinfo.php.

CVE-2012-0939 testlink vulnerability CVSS: 6.5 14 Aug 2014, 14:55 UTC

Multiple SQL injection vulnerabilities in TestLink 1.8.5b and earlier allow remote authenticated users with the Requirement view permission to execute arbitrary SQL commands via the req_spec_id parameter to (1) reqSpecAnalyse.php, (2) reqSpecPrint.php, or (3) reqSpecView.php in requirements/. NOTE: some of these details are obtained from third party information.

CVE-2012-0938 testlink vulnerability CVSS: 6.5 14 Aug 2014, 14:55 UTC

Multiple SQL injection vulnerabilities in TestLink 1.9.3, 1.8.5b, and earlier allow remote authenticated users with certain permissions to execute arbitrary SQL commands via the root_node parameter in the display_children function to (1) getrequirementnodes.php or (2) gettprojectnodes.php in lib/ajax/; the (3) cfield_id parameter in an edit action to lib/cfields/cfieldsEdit.php; the (4) id parameter in an edit action or (5) plan_id parameter in a create action to lib/plan/planMilestonesEdit.php; or the req_spec_id parameter to (6) reqImport.php or (7) in a create action to reqEdit.php in lib/requirements/. NOTE: some of these details are obtained from third party information.