Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

TIMLEGGE — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting TIMLEGGE. AI-powered Chinese analysis, POCs, and references for each vulnerability.

TIMLEGGE develops enterprise software solutions for supply chain management, with a core focus on logistics optimization and inventory tracking. Historically, the organization's products have been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from insufficient input validation and access control flaws. While no major public security incidents have been documented, TIMLEGGE's four recorded CVEs highlight persistent weaknesses in authentication mechanisms and secure coding practices. The organization's security posture appears reactive rather than proactive, with vulnerabilities typically addressed only after public disclosure, leaving customers exposed to potential exploitation between discovery and patch deployment.

CVE ID Title CVSS Severity Published
CVE-2026-18568 XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic check — XML::Sig CWE-347 - - 2026-08-03
CVE-2026-18092 Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree — Net::SAML2 CWE-347 - - 2026-08-03
CVE-2026-9487 XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID — XML::Sig CWE-347 - - 2026-08-03
CVE-2026-9390 XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup — XML::Sig CWE-643 - - 2026-08-03
CVE-2026-18108 Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature — Net::SAML2 CWE-347 - - 2026-08-03
CVE-2026-18089 Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured — Net::SAML2 CWE-347 - - 2026-08-03
CVE-2026-14570 Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery — Crypt::DSA CWE-330 - - 2026-07-05
CVE-2026-12205 Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery — Crypt::DSA CWE-323 - - 2026-06-15
CVE-2026-8704 Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified — Crypt::DSA CWE-552 - - 2026-05-15
CVE-2026-8700 Crypt::DSA versions before 1.20 for Perl generate seeds using rand — Crypt::DSA CWE-331 - - 2026-05-15
CVE-2026-30909 Crypt::NaCl::Sodium versions through 2.002 for Perl has potential integer overflows — Crypt::NaCl::Sodium CWE-190 9.1 - 2026-03-08
CVE-2026-2588 Crypt::NaCl::Sodium versions through 2.001 for Perl has an integer overflow flaw on 32-bit systems — Crypt::NaCl::Sodium CWE-190 9.1AI Critical AI 2026-02-22
CVE-2025-40934 XML-Sig prior to 0.68 for Perl improperly validates XML without signatures — XML::Sig CWE-347 7.5AI High AI 2025-11-26
CVE-2020-36846 IO::Compress::Brotli versions prior to 0.007 for Perl have an integer overflow in the bundled Brotli C library — IO::Compress::Brotli CWE-1395 7.5AI High AI 2025-05-30

This page lists every published CVE security advisory associated with TIMLEGGE. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.