Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Projectsend Subscribe
Filtered by product Projectsend
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-9580 1 Projectsend 1 Projectsend 2017-09-07 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) r561 allows remote attackers to inject arbitrary web script or HTML via the Description field in a file upload. NOTE: this issue was originally incorrectly mapped to CVE-2014-1155; see CVE-2014-1155 for more information.
CVE-2017-9741 1 Projectsend 1 Projectsend 2017-06-29 7.5 HIGH 9.8 CRITICAL
install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to replacing TABLES_PREFIX in the configuration file.