tinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell metacharacters (such as a backquote or a dollar sign) in titles, messages, and other input data. NOTE: this issue exists because of an incomplete fix for CVE-2020-36767, which only considered single and double quote characters.
History

Tue, 10 Mar 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Vareille tinyfiledialogs
CPEs cpe:2.3:a:vareille:tiny_file_dialogs:*:*:*:*:*:*:*:* cpe:2.3:a:vareille:tinyfiledialogs:*:*:*:*:*:*:*:*
Vendors & Products Vareille tiny File Dialogs
Vareille tinyfiledialogs

Mon, 09 Sep 2024 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-10-30T00:00:00.000Z

Updated: 2024-09-09T20:34:10.445Z

Reserved: 2023-10-30T00:00:00.000Z

Link: CVE-2023-47104

cve-icon Vulnrichment

Updated: 2024-08-02T21:01:22.686Z

cve-icon NVD

Status : Analyzed

Published: 2023-10-30T19:15:08.343

Modified: 2026-03-10T19:09:12.560

Link: CVE-2023-47104

cve-icon Redhat

No data.