CVE-2018-19109: Tianti Project Tianti

High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.

tianti 2.3 allows remote authenticated users to bypass intended permission restrictions by visiting tianti-module-admin/cms/column/list directly to read the column list page or edit a column.

Affected products

Published 2018-11-08. Last modified 2026-06-17.