tarteaucitron

tarteaucitron 1

tarteaucitron 1

Third-party maintenance for the tarteaucitron 1 costs 40-70% less than the OEM support contract, with 24/7 engineering support and same-day replacement parts.

Specifications

product
tarteaucitron
release
1
product Label
tarteaucitron
release Label
1
codename
lts
latest Version
1.34.0
release Date
2018-08-28
maintained
true
source Url
https://endoflife.date/tarteaucitron

Get Third Party Support

Your quote will be sent to this address.

By submitting this form, you agree to our Privacy Policy.

OEM vs. 3rd Party Support

See how 3rd party maintenance compares to traditional OEM support for your tarteaucitron 1. Get the same level of service at a fraction of the cost.

FeatureOEM Support3rd Party Support
Post-EOSL Support
24/7/365 Support
Same-Day Parts Replacement
Limited
Mixed-Vendor Support
Flexible Contract Terms
Annual Only
Month-to-Month Available
Asset Lifecycle Extension
OEM-Trained Engineers

Why Choose 3rd Party Support for tarteaucitron 1?

Save 40-70%

Dramatically reduce your maintenance costs while maintaining the same level of support coverage.

Extend Asset Life

Continue using your tarteaucitron 1 well beyond the OEM end-of-life date.

24/7 Expert Support

OEM-trained engineers available around the clock with same-day parts replacement.

tarteaucitron 1 Support: Frequently Asked Questions

Is the tarteaucitron 1 still supported?

Yes. The tarteaucitron 1 is currently supported, and third-party maintenance is available as an alternative to the OEM contract at 40-70% lower cost.

How much does third-party support for the tarteaucitron 1 cost?

Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location β€” request a quote and we respond within 24 hours.

Known Vulnerabilities Affecting tarteaucitron 1

5 published CVEs affect the tarteaucitron 1. Our 24/7 engineers help you assess exposure, prioritize fixes and apply available patches.

CVESeverityCVSSPublishedSummary
CVE-2025-31475MEDIUM5.5Apr 7, 2025tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where the addOrUpdate function, used for applying custom texts, did not properly validate input. This allowed an attacker with direct access to the site's source code or a CMS plugin to manipulate JavaScript object prototypes, leading to potential security risks such as data corruption or unintended code execution. An attacker with high privileges could exploit this v
CVE-2025-31138MEDIUM5.5Apr 7, 2025tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where user-controlled inputs for element dimensions (width and height) were not properly validated. This allowed an attacker with direct access to the site's source code or a CMS plugin to set values like 100%;height:100%;position:fixed;, potentially covering the entire viewport and facilitating clickjacking attacks. An attacker with high privileges could exploit this
CVE-2025-31476MEDIUM4.8Apr 7, 2025tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js, allowing a user with high privileges (access to the site's source code or a CMS plugin) to enter a URL containing an insecure scheme such as javascript:alert(). Before the fix, URL validation was insufficient, which could allow arbitrary JavaScript execution if a user clicked on a malicious link. An attacker with high privileges could insert a link exploiting an insecure URL scheme,
CVE-2026-22809MEDIUM4.4Jan 13, 2026tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.29.0, a Regular Expression Denial of Service (ReDoS) vulnerability was identified in tarteaucitron.js in the handling of the issuu_id parameter. This vulnerability is fixed in 1.29.0.
CVE-2025-48939MEDIUM4.2Jul 3, 2025tarteaucitron.js is a compliant and accessible cookie banner. Prior to version 1.22.0, a vulnerability was identified in tarteaucitron.js where document.currentScript was accessed without verifying that it referenced an actual <script> element. If an attacker injected an HTML element, it could clobber the document.currentScript property. This causes the script to resolve incorrectly to an element instead of the <script> tag, leading to unexpected behavior or failure to load the script path corre
Get Third Party Support
tarteaucitron 1
Save 40-70% vs OEM
Get Third Party Support