Home/Product/interact
Product

interact

18 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-6416
>= 3.2.0 and < 3.2.202
Tanium addressed an uncontrolled resource consumption vulnerability in Interact.
2.7LOW
CVE-2026-2350
>= 3.2.0 and < 3.2.196
Tanium addressed an insertion of sensitive information into log file vulnerability in Interact and TDS.
6.5MEDIUM
CVE-2025-15289
>= 3.1.0 and < 3.1.337
Tanium addressed an improper access controls vulnerability in Interact.
3.1LOW
CVE-2025-15288
>= 3.5.0 and < 3.5.90
Tanium addressed an improper access controls vulnerability in Interact.
3.1LOW
CVE-2023-5659
<= 3.0.7
The Interact: Embed A Quiz On Your Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'intera
6.4MEDIUM
CVE-2023-41103
all versions
Interact 7.9.79.5 allows stored Cross-site Scripting (XSS) attacks in several locations, allowing an attacker to store a JavaScrip
5.4MEDIUM
CVE-2016-5889
all versions
IBM Interact 8.6, 9.0, 9.1, and 10.0 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciou
8.8HIGH
CVE-2016-5888
all versions
IBM Interact 8.6, 9.0, 9.1, and 10.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav
5.4MEDIUM
CVE-2008-3868
all versions
Cross-site request forgery (CSRF) vulnerability in Interact 2.4.1 allows remote attackers to hijack the authentication of super ad
CVE-2008-3867
all versions
SQL injection vulnerability in spaces/emailuser.php in Interact 2.4.1 allows remote attackers to execute arbitrary SQL commands vi
CVE-2008-3384
all versions
Multiple directory traversal vulnerabilities in help/help.php in Interact Learning Community Environment Interact 2.4.1 allow remo
CVE-2008-2220
all versions
Multiple PHP remote file inclusion vulnerabilities in Interact Learning Community Environment Interact 2.4.1, when register_global
CVE-2007-4177
<= 2.3.1
Multiple cross-site scripting (XSS) vulnerabilities in Interact before 2.4 allow remote attackers to inject arbitrary web script o
CVE-2007-3328
all versions
Multiple cross-site scripting (XSS) vulnerabilities in Interact 2.4 beta 1 allow remote attackers to inject arbitrary web script o
CVE-2006-4448
all versions
Multiple PHP remote file inclusion vulnerabilities in interact 2.2, when register_globals is enabled, allow remote attackers to ex
CVE-2006-1644
<= 2.1.1
login.php in Interact 2.1.1 generates different responses depending on whether or not a username is valid, which allows remote att
CVE-2006-1643
<= 2.1.1
SQL injection vulnerability in login.php in Interact 2.1.1 allows remote attackers to execute arbitrary SQL commands via the user_
CVE-2006-1642
<= 2.1.1
Cross-site scripting (XSS) vulnerability in Interact 2.1.1 allows remote attackers to inject arbitrary web script or HTML via (1)
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin