Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zephyr Project Manager MEDIUM 6.1
CVE-2025-32526

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager zephyr-proje…

Fix: after 3.3.102
Fix from $1,600 2025-04-17
Zephyr Project Manager MEDIUM 5.4
CVE-2024-43915

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager allow…

Fix: 3.3.103+
Fix from $1,600 2024-08-26
Zephyr Project Manager CRITICAL 9.8
CVE-2024-43322

Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from …

Fix: 3.3.101+
Fix from $2,300 2024-08-18
Zephyr Project Manager HIGH 8.1
CVE-2024-7624

The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is …

Fix: 3.3.102+
Fix from $1,950 2024-08-15
Zephyr Project Manager MEDIUM 5.4
CVE-2024-7356

The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘filename’ parameter in all versions up to, and …

Fix: 3.3.101+
Fix from $1,600 2024-08-03
Zephyr Project Manager HIGH 7.5
CVE-2024-38761

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Mana…

Fix: 3.3.100+
Fix from $1,950 2024-08-01
Zephyr Project Manager HIGH 8.8
CVE-2024-37484

Improper Privilege Management vulnerability in Dylan James Zephyr Project Manager allows Privilege Escalation.This issue affects Zephyr Project Manag…

Fix: 3.3.99+
Fix from $1,950 2024-07-09
Zephyr Project Manager MEDIUM 5.4
CVE-2022-2839

The Zephyr Project Manager WordPress plugin before 3.2.55 does not have any authorisation as well as CSRF in all its AJAX actions, allowing unauthent…

Fix: 3.2.55+
Fix from $1,600 2022-10-03
Zephyr Project Manager MEDIUM 5.4
CVE-2022-3333

A vulnerability, which was classified as problematic, was found in Zephyr Project Manager up to 3.2.4. Affected is an unknown function of the file /v…

Fix: 3.2.5+
Fix from $1,600 2022-09-28
Zephyr Project Manager CRITICAL 9.8
CVE-2022-2840EPSS 10%

The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via vari…

Fix: 3.2.5+
Fix from $2,300 2022-09-19