Vulnerability index

Browse CVEs

17 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Projectsend CRITICAL 9.8
CVE-2023-53980

ProjectSend r1605 contains a remote code execution vulnerability that allows attackers to upload malicious files by manipulating file extensions. Att…

Mitigation only
Fix from $2,300 2025-12-22
Projectsend HIGH 7.5
CVE-2023-53930

ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manip…

No fix yet
Fix from $1,950 2025-12-17
Projectsend HIGH 8.0
CVE-2023-53905

ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into user profile names. Attack…

No fix yet
Fix from $1,950 2025-12-17
Projectsend MEDIUM 5.7
CVE-2017-20101

A vulnerability, which was classified as problematic, was found in ProjectSend r754. This affects an unknown part of the file process.php?do=zip_down…

No fix yet
Fix from $1,600 2022-06-27
Projectsend CRITICAL 9.8
CVE-2021-40887

Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for files[] parameter, an attacke…

No fix yet
Fix from $2,300 2021-10-11
Projectsend HIGH 8.1
CVE-2021-40884

Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids parameter in files-edit.php a…

No fix yet
Fix from $1,950 2021-10-11
Projectsend MEDIUM 6.5
CVE-2021-40886

Projectsend version r1295 is affected by a directory traversal vulnerability. A user with Uploader role can add value `2` for `chunks` parameter to b…

No fix yet
Fix from $1,600 2021-10-11
Projectsend MEDIUM 5.4
CVE-2021-40888

Projectsend version r1295 is affected by Cross Site Scripting (XSS) due to lack of sanitization when echo output data in returnFilesIds() function. A…

No fix yet
Fix from $1,600 2021-10-11
Projectsend MEDIUM 6.1
CVE-2018-7202

An issue was discovered in ProjectSend before r1053. XSS exists in the "Name" field on the My Account page.

Mitigation only
Fix from $1,600 2019-05-22
Projectsend HIGH 8.8
CVE-2019-11378

An issue was discovered in ProjectSend r1053. upload-process-form.php allows finished_files[]=../ directory traversal. It is possible for users to re…

No fix yet
Fix from $1,950 2019-04-20
Projectsend CRITICAL 9.8
CVE-2016-10732

ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or process-zip-d…

Mitigation only
Fix from $2,300 2018-10-29
Projectsend CRITICAL 9.8
CVE-2016-10733

ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string.

Mitigation only
Fix from $2,300 2018-10-29
Projectsend CRITICAL 9.8
CVE-2016-10734

ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.

Mitigation only
Fix from $2,300 2018-10-29
Projectsend CRITICAL 9.8
CVE-2016-10731

ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request param…

Mitigation only
Fix from $2,300 2018-10-29
Projectsend CRITICAL 9.8
CVE-2017-9741

install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to replacing TA…

No fix yet
Fix from $2,300 2017-06-18
Projectsend MEDIUM 6.5
CVE-2015-2564

SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to execute arbitrary SQL command…

No fix yet
Fix from $1,600 2015-03-20
Projectsend HIGH 7.5
CVE-2014-9567EPSS 43%

Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows remote attackers to execute arbi…

No fix yet
Fix from $1,950 2015-01-07