Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

TIMLEGGE — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting TIMLEGGE. AI-powered Chinese analysis, POCs, and references for each vulnerability.

TIMLEGGE develops enterprise software solutions for supply chain management, with a core focus on logistics optimization and inventory tracking. Historically, the organization's products have been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from insufficient input validation and access control flaws. While no major public security incidents have been documented, TIMLEGGE's four recorded CVEs highlight persistent weaknesses in authentication mechanisms and secure coding practices. The organization's security posture appears reactive rather than proactive, with vulnerabilities typically addressed only after public disclosure, leaving customers exposed to potential exploitation between discovery and patch deployment.

CVE IDTitleCVSSSeverityPublished
CVE-2026-18568 XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic check — XML::SigCWE-347--2026-08-03
CVE-2026-18092 Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree — Net::SAML2CWE-347--2026-08-03
CVE-2026-9487 XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID — XML::SigCWE-347--2026-08-03
CVE-2026-9390 XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup — XML::SigCWE-643--2026-08-03
CVE-2026-18108 Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature — Net::SAML2CWE-347--2026-08-03
CVE-2026-18089 Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured — Net::SAML2CWE-347--2026-08-03
CVE-2026-14570 Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery — Crypt::DSACWE-330--2026-07-05
CVE-2026-12205 Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery — Crypt::DSACWE-323--2026-06-15
CVE-2026-8704 Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified — Crypt::DSACWE-552--2026-05-15
CVE-2026-8700 Crypt::DSA versions before 1.20 for Perl generate seeds using rand — Crypt::DSACWE-331--2026-05-15
CVE-2026-30909 Crypt::NaCl::Sodium versions through 2.002 for Perl has potential integer overflows — Crypt::NaCl::SodiumCWE-190 9.1 -2026-03-08
CVE-2026-2588 Crypt::NaCl::Sodium versions through 2.001 for Perl has an integer overflow flaw on 32-bit systems — Crypt::NaCl::SodiumCWE-190 9.1AICriticalAI2026-02-22
CVE-2025-40934 XML-Sig prior to 0.68 for Perl improperly validates XML without signatures — XML::SigCWE-347 7.5AIHighAI2025-11-26
CVE-2020-36846 IO::Compress::Brotli versions prior to 0.007 for Perl have an integer overflow in the bundled Brotli C library — IO::Compress::BrotliCWE-1395 7.5AIHighAI2025-05-30

This page lists every published CVE security advisory associated with TIMLEGGE. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.