Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Leantime MEDIUM 5.4
CVE-2025-28254

Cross Site Scripting vulnerability in Leantime v3.2.1 and before allows an authenticated attacker to execute arbitrary code and obtain sensitive info…

Fix: 3.3.0+
Fix from $1,600 2025-03-28
Leantime HIGH 8.8
CVE-2024-27474

Leantime 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF). This vulnerability allows malicious actors to perform unauthorized actions on beha…

No fix yet
Fix from $1,950 2024-04-10
Leantime MEDIUM 6.1
CVE-2024-27477

In Leantime 3.0.6, a Cross-Site Scripting vulnerability exists within the ticket creation and modification functionality, allowing attackers to injec…

No fix yet
Fix from $1,600 2024-04-10
Leantime HIGH 7.6
CVE-2024-27705

Cross Site Scripting vulnerability in Leantime v3.0.6 allows attackers to execute arbitrary code via upload of crafted PDF file to the files/browse e…

No fix yet
Fix from $1,950 2024-04-03
Leantime MEDIUM 5.4
CVE-2024-27703

Cross Site Scripting vulnerability in Leantime 3.0.6 allows a remote attacker to execute arbitrary code via the to-do title parameter.

No fix yet
Fix from $1,600 2024-03-13
Leantime MEDIUM 6.5
CVE-2023-45826

Leantime is an open source project management system. A 'userId' variable in `app/domain/files/repositories/class.files.php` is not parameterized. An…

Fix: 2.4+
Fix from $1,600 2023-10-19
Leantime MEDIUM 5.4
CVE-2023-33961

Leantime is a lean open source project management system. Starting in version 2.3.21, an authenticated user with commenting privileges can inject mal…

Mitigation only
Fix from $1,600 2023-05-30
Leantime HIGH 8.8
CVE-2020-5292

Leantime before versions 2.0.15 and 2.1-beta3 has a SQL Injection vulnerability. The impact is high. Malicious users/attackers can execute arbitrary …

Fix: 2.0.15+
Fix from $1,950 2020-03-31