Vulnerability index

Browse CVEs

27 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2023-53971 WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functi… Webtareas No fix yet Fix from $1,9502025-12-22 HIGH 7.5 CVE-2023-53972 WebTareas 2.4 contains a SQL injection vulnerability in the webTareasSID cookie parameter that allows unauthenticated attackers to manipulate databas… Webtareas No fix yet Fix from $1,9502025-12-22 MEDIUM 5.4 CVE-2022-44960 webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /general/search.php?searchtype=simple. This vul… Webtareas No fix yet Fix from $1,6002022-12-02 MEDIUM 5.4 CVE-2022-44961 webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /forums/editforum.php. This vulnerability allow… Webtareas No fix yet Fix from $1,6002022-12-02 MEDIUM 5.4 CVE-2022-44962 webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /calendar/viewcalendar.php. This vulnerability … Webtareas No fix yet Fix from $1,6002022-12-02 MEDIUM 5.4 CVE-2022-44953 webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /linkedcontent/listfiles.php. This vulnerabilit… Webtareas No fix yet Fix from $1,6002022-12-02 MEDIUM 5.4 CVE-2022-44954 webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /contacts/listcontacts.php. This vulnerability … Webtareas No fix yet Fix from $1,6002022-12-02 MEDIUM 5.4 CVE-2022-44955 webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the Chat function. This vulnerability allows attackers to exe… Webtareas No fix yet Fix from $1,6002022-12-02 MEDIUM 5.4 CVE-2022-44956 webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /projects/listprojects.php. This vulnerability … Webtareas No fix yet Fix from $1,6002022-12-02 MEDIUM 5.4 CVE-2022-44957 webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /clients/listclients.php. This vulnerability al… Webtareas No fix yet Fix from $1,6002022-12-02 MEDIUM 5.4 CVE-2022-44959 webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /meetings/listmeetings.php. This vulnerability … Webtareas No fix yet Fix from $1,6002022-12-02 CRITICAL 9.8 CVE-2022-44290 webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php. Webtareas Mitigation only Fix from $2,3002022-12-02 CRITICAL 9.8 CVE-2022-44291 webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php. Webtareas Mitigation only Fix from $2,3002022-12-02 MEDIUM 5.4 CVE-2021-36608 Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /projects/editproject.php. Webtareas No fix yet Fix from $1,6002022-06-16 MEDIUM 5.4 CVE-2021-36609 Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /linkedcontent/editfolder.php. Webtareas No fix yet Fix from $1,6002022-06-16 CRITICAL 9.8 CVE-2021-43481EPSS 6% An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php. Webtareas 2.4+ Fix from $2,3002022-04-20 HIGH 8.8 CVE-2021-41916 A Cross-Site Request Forgery (CSRF) vulnerability in webTareas version 2.4 and earlier allows a remote attacker to create a new administrative profil… Webtareas after 2.4 Fix from $1,9502021-10-08 HIGH 8.8 CVE-2021-41919 webTareas version 2.4 and earlier allows an authenticated user to arbitrarily upload potentially dangerous files without restrictions. This is workin… Webtareas after 2.4 Fix from $1,9502021-10-08 HIGH 7.5 CVE-2021-41920 webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/libr… Webtareas after 2.4 Fix from $1,9502021-10-08 MEDIUM 5.4 CVE-2021-41917 webTareas version 2.4 and earlier allows an authenticated user to store arbitrary web script or HTML by creating or editing a client name in the clie… Webtareas after 2.4 Fix from $1,6002021-10-08 MEDIUM 5.4 CVE-2021-41918 webTareas version 2.4 and earlier allows an authenticated user to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied … Webtareas after 2.4 Fix from $1,6002021-10-08 MEDIUM 6.5 CVE-2020-23069 Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a malicious user read arbitrary fi… Webtareas No fix yet Fix from $1,6002021-08-18 HIGH 7.5 CVE-2020-25733 webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types. Webtareas after 2.1 Fix from $1,9502020-09-18 MEDIUM 6.1 CVE-2020-25735 webTareas through 2.1 allows XSS in clients/editclient.php, extensions/addextension.php, administration/add_announcement.php, administration/departme… Webtareas after 2.1 Fix from $1,6002020-09-18 MEDIUM 5.3 CVE-2020-25734 webTareas through 2.1 allows files/Default/ Directory Listing. Webtareas after 2.1 Fix from $1,6002020-09-18 MEDIUM 5.4 CVE-2020-23660 webTareas v2.1 is affected by Cross Site Scripting (XSS) on "Search." Webtareas No fix yet Fix from $1,6002020-08-26 MEDIUM 6.1 CVE-2020-14973 The loginForm within the general/login.php webpage in webTareas 2.0p8 suffers from a Reflected Cross Site Scripting (XSS) vulnerability via the query… Webtareas No fix yet Fix from $1,6002020-06-22