tarteaucitron 1
tarteaucitron 1
Third-party maintenance for the tarteaucitron 1 costs 40-70% less than the OEM support contract, with 24/7 engineering support and same-day replacement parts.
Specifications
- product
- tarteaucitron
- release
- 1
- product Label
- tarteaucitron
- release Label
- 1
- codename
- lts
- latest Version
- 1.34.0
- release Date
- 2018-08-28
- maintained
- true
- source Url
- https://endoflife.date/tarteaucitron
OEM vs. 3rd Party Support
See how 3rd party maintenance compares to traditional OEM support for your tarteaucitron 1. Get the same level of service at a fraction of the cost.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| 24/7/365 Support | ||
| Same-Day Parts Replacement | Limited | |
| Mixed-Vendor Support | ||
| Flexible Contract Terms | Annual Only | Month-to-Month Available |
| Asset Lifecycle Extension | ||
| OEM-Trained Engineers |
Why Choose 3rd Party Support for tarteaucitron 1?
Save 40-70%
Dramatically reduce your maintenance costs while maintaining the same level of support coverage.
Extend Asset Life
Continue using your tarteaucitron 1 well beyond the OEM end-of-life date.
24/7 Expert Support
OEM-trained engineers available around the clock with same-day parts replacement.
tarteaucitron 1 Support: Frequently Asked Questions
Is the tarteaucitron 1 still supported?
Yes. The tarteaucitron 1 is currently supported, and third-party maintenance is available as an alternative to the OEM contract at 40-70% lower cost.
How much does third-party support for the tarteaucitron 1 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location β request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting tarteaucitron 1
5 published CVEs affect the tarteaucitron 1. Our 24/7 engineers help you assess exposure, prioritize fixes and apply available patches.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2025-31475 | MEDIUM | 5.5 | Apr 7, 2025 | tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where the addOrUpdate function, used for applying custom texts, did not properly validate input. This allowed an attacker with direct access to the site's source code or a CMS plugin to manipulate JavaScript object prototypes, leading to potential security risks such as data corruption or unintended code execution. An attacker with high privileges could exploit this v |
| CVE-2025-31138 | MEDIUM | 5.5 | Apr 7, 2025 | tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where user-controlled inputs for element dimensions (width and height) were not properly validated. This allowed an attacker with direct access to the site's source code or a CMS plugin to set values like 100%;height:100%;position:fixed;, potentially covering the entire viewport and facilitating clickjacking attacks. An attacker with high privileges could exploit this |
| CVE-2025-31476 | MEDIUM | 4.8 | Apr 7, 2025 | tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js, allowing a user with high privileges (access to the site's source code or a CMS plugin) to enter a URL containing an insecure scheme such as javascript:alert(). Before the fix, URL validation was insufficient, which could allow arbitrary JavaScript execution if a user clicked on a malicious link. An attacker with high privileges could insert a link exploiting an insecure URL scheme, |
| CVE-2026-22809 | MEDIUM | 4.4 | Jan 13, 2026 | tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.29.0, a Regular Expression Denial of Service (ReDoS) vulnerability was identified in tarteaucitron.js in the handling of the issuu_id parameter. This vulnerability is fixed in 1.29.0. |
| CVE-2025-48939 | MEDIUM | 4.2 | Jul 3, 2025 | tarteaucitron.js is a compliant and accessible cookie banner. Prior to version 1.22.0, a vulnerability was identified in tarteaucitron.js where document.currentScript was accessed without verifying that it referenced an actual <script> element. If an attacker injected an HTML element, it could clobber the document.currentScript property. This causes the script to resolve incorrectly to an element instead of the <script> tag, leading to unexpected behavior or failure to load the script path corre |