Skip to content
COOEY

FAIL › dossier

taogogo

VENDOR

· dossier confidence 80%

taogogo develops taocms, a content management system that suffered two critical remote code execution vulnerabilities in 2022, allowing attackers to execute arbitrary code by modifying core configuration files.

PROFILE
Categorysoftware vendorWhat they dotaogogo is a vendor of taocms, a content management system.
SECURITY POSTURE

The company has a poor security posture, evidenced by two critical remote code execution vulnerabilities in 2022 that allowed arbitrary code execution via config file modification and .htaccess editing.

Notable failures
  • CVE-2022-36262 critical RCE via config.php modification
  • CVE-2022-25578 critical RCE via .htaccess editing
Patterns: repeated critical RCE vulnerabilities in CMS core files
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2022-08-15 CVE-2022-36262 critical An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modifying config.php.
2022-03-18 CVE-2022-25578 critical taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file.
DOSSIER SOURCES
Open questions: taogogo's founding year · taogogo's headquarters location · taogogo's company size · taogogo's ownership structure · taogogo's official website
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-21 04:01:53.795254+00:00