CVE-2019-13144: Mytinytodo

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

myTinyTodo 1.3.3 through 1.4.3 allows CSV Injection. This is fixed in 1.5.

Affected products

  • Mytinytodo Mytinytodo: from 1.3.3, up to and including 1.4.3

Published 2019-07-05. Last modified 2026-06-17.