CVE-2025-22649
- EPSS 0.25%
- Veröffentlicht 27.03.2025 15:15:57
- Zuletzt bearbeitet 23.04.2026 15:23:19
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager wedevs-project-manager allows Stored XSS.This issue affects WP Project Manager: from n/a through <= 2.6.22.
CVE-2024-13500
- EPSS 0.42%
- Veröffentlicht 15.02.2025 12:15:30
- Zuletzt bearbeitet 24.02.2025 12:33:48
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.6.17 due to ...
CVE-2024-13752
- EPSS 0.51%
- Veröffentlicht 15.02.2025 10:15:08
- Zuletzt bearbeitet 24.02.2025 12:30:24
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check in the '/pm/v2/settings/notice' endpoint all ...
CVE-2024-12195
- EPSS 0.44%
- Veröffentlicht 04.01.2025 12:15:22
- Zuletzt bearbeitet 05.02.2025 16:50:05
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to SQL Injection via the 'project_id' parameter of the /wp-json/pm/v2/projects/2/task-lists REST API endpoin...
CVE-2024-10548
- EPSS 0.39%
- Veröffentlicht 19.12.2024 02:15:22
- Zuletzt bearbeitet 05.02.2025 16:49:13
The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Project Task List ('/wp-json/pm/v2/projects/1/task-lists') REST API endpoint. This makes it possible for ...
CVE-2023-40003
- EPSS 0.49%
- Veröffentlicht 13.12.2024 15:15:21
- Zuletzt bearbeitet 29.04.2026 10:16:14
Missing Authorization vulnerability in weDevs WP Project Manager wedevs-project-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Project Manager: from n/a through <= 2.6.7.
CVE-2024-12015
- EPSS 0.51%
- Veröffentlicht 02.12.2024 14:15:05
- Zuletzt bearbeitet 15.04.2026 00:35:42
The 'Project Manager' WordPress Plugin is affected by an authenticated SQL injection vulnerability in the 'orderby' parameter in the '/pm/v2/activites' route.
CVE-2024-10520
- EPSS 0.31%
- Veröffentlicht 20.11.2024 12:15:18
- Zuletzt bearbeitet 05.02.2025 16:51:57
The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' method of the 'Create_Milestone', 'Create_Task_List', 'Create_Task', and 'Delete_Task' classes in version ...
CVE-2024-10174
- EPSS 0.66%
- Veröffentlicht 13.11.2024 04:15:03
- Zuletzt bearbeitet 05.02.2025 16:48:14
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.13 via the 'Abstract_Permissio...
CVE-2023-49860
- EPSS 0.39%
- Veröffentlicht 14.12.2023 17:15:09
- Zuletzt bearbeitet 28.04.2026 19:22:31
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts allows Stored XSS.This issue affects W...