CVE-2026-100900
- EPSS 0.16%
- Veröffentlicht 28.09.2026 02:30:09
- Zuletzt bearbeitet 01.10.2026 15:17:19
A vulnerability has been found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1. Affected is the function updateJiraProjects of the file /jira-import of the component Jira Import. The manipulation of the argument host/username/t...
CVE-2026-100898
- EPSS 0.19%
- Veröffentlicht 28.09.2026 02:17:19
- Zuletzt bearbeitet 28.09.2026 15:16:04
A vulnerability was detected in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/2.0.0-beta1. This affects the function whereRaw of the file app/Filament/Widgets/Timesheet/ActivitiesReport.php of the component Timesheet Dashboard. Performing a ...
CVE-2026-100899
- EPSS 0.19%
- Veröffentlicht 28.09.2026 02:15:16
- Zuletzt bearbeitet 28.09.2026 15:16:04
A flaw has been found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1. This impacts the function whereRaw of the file app/Filament/Widgets/Timesheet/MonthlyReport.php of the component Timesheet Dashboard. Executing a manipulati...
CVE-2026-10285
- EPSS 0.23%
- Veröffentlicht 01.06.2026 19:15:26
- Zuletzt bearbeitet 22.07.2026 08:10:00
A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper::recordUpdated of the file app/Helpers/KanbanScrumHelper.php of the component Ticket Handler. The manipulatio...
CVE-2026-10284
- EPSS 0.23%
- Veröffentlicht 01.06.2026 19:00:09
- Zuletzt bearbeitet 22.07.2026 08:10:00
A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerability is the function editComment/doDeleteComment of the file app/Filament/Resources/TicketResource/Pages/ViewTicket.php of the component Livewire Han...
CVE-2025-52203
- EPSS 0.32%
- Veröffentlicht 31.07.2025 00:00:00
- Zuletzt bearbeitet 06.08.2025 16:18:51
A stored cross-site scripting (XSS) vulnerability exists in DevaslanPHP project-management v1.2.4. The vulnerability resides in the Ticket Name field, which fails to properly sanitize user-supplied input. An authenticated attacker can inject maliciou...