Vulnerability index

Browse CVEs

26 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-53980 ProjectSend r1605 contains a remote code execution vulnerability that allows attackers to upload malicious files by manipulating file extensions. Att… Projectsend Mitigation only Fix from $2,3002025-12-22 HIGH 7.5 CVE-2023-53930 ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manip… Projectsend No fix yet Fix from $1,9502025-12-17 HIGH 8.0 CVE-2023-53905 ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into user profile names. Attack… Projectsend No fix yet Fix from $1,9502025-12-17 CRITICAL 9.8 CVE-2024-11680 KEVEPSS 92% ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw… Projectsend Patch available Fix from $2,3002024-11-26 HIGH 7.5 CVE-2024-7659 A vulnerability, which was classified as problematic, was found in projectsend up to r1605. Affected is the function generate_random_string of the fi… Projectsend Patch available Fix from $1,9502024-08-12 MEDIUM 5.3 CVE-2024-7658 A vulnerability, which was classified as problematic, has been found in projectsend up to r1605. This issue affects the function get_preview of the f… Projectsend Patch available Fix from $1,6002024-08-12 MEDIUM 5.7 CVE-2017-20101 A vulnerability, which was classified as problematic, was found in ProjectSend r754. This affects an unknown part of the file process.php?do=zip_down… Projectsend No fix yet Fix from $1,6002022-06-27 CRITICAL 9.8 CVE-2021-40887 Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for files[] parameter, an attacke… Projectsend No fix yet Fix from $2,3002021-10-11 HIGH 8.1 CVE-2021-40884 Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids parameter in files-edit.php a… Projectsend No fix yet Fix from $1,9502021-10-11 MEDIUM 6.5 CVE-2021-40886 Projectsend version r1295 is affected by a directory traversal vulnerability. A user with Uploader role can add value `2` for `chunks` parameter to b… Projectsend No fix yet Fix from $1,6002021-10-11 MEDIUM 5.4 CVE-2021-40888 Projectsend version r1295 is affected by Cross Site Scripting (XSS) due to lack of sanitization when echo output data in returnFilesIds() function. A… Projectsend No fix yet Fix from $1,6002021-10-11 HIGH 7.5 CVE-2020-28874 reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not proper… Projectsend Patch available Fix from $1,9502021-01-26 HIGH 8.8 CVE-2018-7201 CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel. Projectsend 1053+ Fix from $1,9502019-05-22 MEDIUM 6.1 CVE-2018-7202 An issue was discovered in ProjectSend before r1053. XSS exists in the "Name" field on the My Account page. Projectsend Mitigation only Fix from $1,6002019-05-22 HIGH 7.5 CVE-2019-11492 ProjectSend before r1070 writes user passwords to the server logs. Projectsend 1070+ Fix from $1,9502019-04-26 MEDIUM 6.1 CVE-2019-11533 Cross-site scripting (XSS) vulnerability in ProjectSend before r1070 allows remote attackers to inject arbitrary web script or HTML. Projectsend 1070+ Fix from $1,6002019-04-26 HIGH 8.8 CVE-2019-11378 An issue was discovered in ProjectSend r1053. upload-process-form.php allows finished_files[]=../ directory traversal. It is possible for users to re… Projectsend No fix yet Fix from $1,9502019-04-20 CRITICAL 9.8 CVE-2016-10732 ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or process-zip-d… Projectsend Mitigation only Fix from $2,3002018-10-29 CRITICAL 9.8 CVE-2016-10733 ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string. Projectsend Mitigation only Fix from $2,3002018-10-29 CRITICAL 9.8 CVE-2016-10734 ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php. Projectsend Mitigation only Fix from $2,3002018-10-29 CRITICAL 9.8 CVE-2016-10731 ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request param… Projectsend Mitigation only Fix from $2,3002018-10-29 MEDIUM 6.1 CVE-2017-9783 Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote attacker… Projectsend Patch available Fix from $1,6002018-03-06 MEDIUM 6.1 CVE-2017-9786 Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote attacker… Projectsend Patch available Fix from $1,6002018-03-06 CRITICAL 9.8 CVE-2017-9741 install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to replacing TA… Projectsend No fix yet Fix from $2,3002017-06-18 MEDIUM 6.5 CVE-2015-2564 SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to execute arbitrary SQL command… Projectsend No fix yet Fix from $1,6002015-03-20 HIGH 7.5 CVE-2014-9567EPSS 43% Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows remote attackers to execute arbi… Projectsend No fix yet Fix from $1,9502015-01-07