Tainacan

Tainacan has 17 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2026; all 17 are fixed as of September 2026. Their average CVSS score is 6.3, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 4 high. 2024 was the busiest year with 8 disclosures.

The most common weakness is Cross-Site Scripting, behind 7 of the records (41%). Other recurring categories include SQL Injection, Missing Authorization.

Every one of the 17 issues recorded for Tainacan has a vendor fix available, so running the current release closes all known holes.

11 independent researchers contributed these findings, most of them (3) reported by Deadbee. Tainacan is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

01234567891025.05.2018Today24.05.20227.2Tainacan <= 0.18.9 - Cross-Site Scripting CVSS 7.2 · 24.05.202220.11.20236.1Tainacan <= 0.20.4 - Reflected Cross-Site Scripting CVSS 6.1 · 20.11.202326.02.20245.3Tainacan <= 0.20.6 - Unauthenticated Sensitive Information Exposure CVSS 5.3 · 26.02.202429.03.20245.3Tainacan <= 0.20.7 - Missing Authorization CVSS 5.3 · 29.03.202420.05.20247.2Tainacan <= 0.21.3 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 20.05.20246.4PDF.js < 4.2.67 - Arbitrary JavaScript Execution CVSS 6.4 · 20.05.20246.4Tainacan <= 0.21.3 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 20.05.202430.07.20246.5Tainacan <= 0.21.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read CVSS 6.5 · 30.07.202409.10.20246.5Tainacan <= 0.21.8 - Authenticated (Subscriber+) SQL Injection CVSS 6.5 · 09.10.202410.10.20246.1Tainacan <= 0.21.10 - Reflected Cross-Site Scripting CVSS 6.1 · 10.10.202422.01.20256.5Tainacan <= 0.21.12 - Authenticated (Subscriber+) SQL Injection CVSS 6.5 · 22.01.202516.05.20255.3Tainacan <= 0.21.14 - Unauthenticated Arbitrary File Deletion CVSS 5.3 · 16.05.202520.11.20255.3Tainacan <= 1.0.0 - Unauthenticated Information Exposure CVSS 5.3 · 20.11.20256.1Tainacan <= 1.0.0 - Reflected Cross-Site Scripting CVSS 6.1 · 20.11.202520.12.20255.3Tainacan <= 1.0.1 - Missing Authorization to Unauthenticated Arbitrary Metadata Section Creation CVSS 5.3 · 20.12.202528.05.20267.5Tainacan <= 1.0.3 - Unauthenticated SQL Injection CVSS 7.5 · 28.05.202607.07.20267.5Tainacan <= 1.0.3 - Unauthenticated SQL Injection via 'geoquery' REST API Parameter CVSS 7.5 · 07.07.2026

Strategic Overview

Avg CVSSMedium
6.3/ 10
Patch Coverage100%
Open

0

Fixed

17

Get automatic notifications for all Tainacan vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.5CVE-2026-6230

Tainacan <= 1.0.3 - Unauthenticated SQL Injection via 'geoquery' REST API Parameter

Read the full analysis

Vulnerability Records

17 records
Tainacan banner
Latestv1.3.0
5.0(12)
100/100
Last Updated
2026-09-03 (9d ago)
Active Installs
1,000+
Downloads
64,969
Requires WP
6.5+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2018-05-25 (8y ago)

Tainacan is an open-source repository platform that turns WordPress into a powerful and flexible environment for managing and publishing digital collections — as easily as writing a blog post. Designed for cultural institutions, research projects, archives, museums, and any kind of digital collection, Tainacan integrates seamlessly with the WordPress block editor and takes full advantage of its ecosystem. Key Features: Free and open source – Licensed under GPLv3: use, modify, and share freely WordPress based – Built to last taking advantage of the power of the WordPress ecosystem and features Compatible with any theme – Use the Tainacan Interface theme or adapt any WordPress theme Easy management – Create collections, define metadata, manage users, and publish content effortlessly Highly customizable – Configure metadata, taxonomies, and filters to match your project’s needs Faceted search – Offer advanced browsing with intuitive custom filters Importing and exporting – Import bulk data from spreadsheets, export in CSV, XLSX, JSON, and other formats API and interoperability – Complete RESTful API with support for metadata mapping to standards such as Dublin Core Gutenberg blocks – Tell stories about your digital archive using a variety of blocks anywhere in your site Support Need help? Find documentation, community support, and development resources at: Website: https://tainacan.org/ Documentation Wiki: https://wiki.tainacan.org/ GitHub: https://github.com/tainacan/tainacan User Forum: https://tainacan.discourse.group/

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C