Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2025-28254
Cross Site Scripting vulnerability in Leantime v3.2.1 and before allows an authenticated attacker to execute arbitrary code and obtain sensitive info…
Leantime
3.3.0+
HIGH 8.8
CVE-2024-27474
Leantime 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF). This vulnerability allows malicious actors to perform unauthorized actions on beha…
Leantime
No fix yet
MEDIUM 6.1
CVE-2024-27477
In Leantime 3.0.6, a Cross-Site Scripting vulnerability exists within the ticket creation and modification functionality, allowing attackers to injec…
Leantime
No fix yet
HIGH 7.6
CVE-2024-27705
Cross Site Scripting vulnerability in Leantime v3.0.6 allows attackers to execute arbitrary code via upload of crafted PDF file to the files/browse e…
Leantime
No fix yet
MEDIUM 5.4
CVE-2024-27703
Cross Site Scripting vulnerability in Leantime 3.0.6 allows a remote attacker to execute arbitrary code via the to-do title parameter.
Leantime
No fix yet
MEDIUM 6.5
CVE-2023-45826
Leantime is an open source project management system. A 'userId' variable in `app/domain/files/repositories/class.files.php` is not parameterized. An…
Leantime
2.4+
MEDIUM 5.4
CVE-2023-33961
Leantime is a lean open source project management system. Starting in version 2.3.21, an authenticated user with commenting privileges can inject mal…
Leantime
Mitigation only
HIGH 8.8
CVE-2020-5292
Leantime before versions 2.0.15 and 2.1-beta3 has a SQL Injection vulnerability. The impact is high. Malicious users/attackers can execute arbitrary …
Leantime
2.0.15+