Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Webtareas Project Subscribe
Total 25 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-25733 1 Webtareas Project 1 Webtareas 2020-09-24 5.0 MEDIUM 7.5 HIGH
webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types.
CVE-2020-25735 1 Webtareas Project 1 Webtareas 2020-09-24 4.3 MEDIUM 6.1 MEDIUM
webTareas through 2.1 allows XSS in clients/editclient.php, extensions/addextension.php, administration/add_announcement.php, administration/departments.php, administration/locations.php, expenses/claim_type.php, projects/editproject.php, and general/newnotifications.php.
CVE-2020-25734 1 Webtareas Project 1 Webtareas 2020-09-24 5.0 MEDIUM 5.3 MEDIUM
webTareas through 2.1 allows files/Default/ Directory Listing.
CVE-2020-23660 1 Webtareas Project 1 Webtareas 2020-08-28 3.5 LOW 5.4 MEDIUM
webTareas v2.1 is affected by Cross Site Scripting (XSS) on "Search."
CVE-2020-14973 1 Webtareas Project 1 Webtareas 2020-06-25 4.3 MEDIUM 6.1 MEDIUM
The loginForm within the general/login.php webpage in webTareas 2.0p8 suffers from a Reflected Cross Site Scripting (XSS) vulnerability via the query string.