CVE-2024-48706
- EPSS 0.09%
 - Published 22.10.2024 17:15:04
 - Last modified 25.03.2025 17:16:11
 
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.php file and (b) managetask.php file respectively.
CVE-2024-48707
- EPSS 0.09%
 - Published 22.10.2024 17:15:04
 - Last modified 25.10.2024 19:11:54
 
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit within managemilestone.php file and (b) action=addpro within admin.php file.
CVE-2024-48708
- EPSS 0.09%
 - Published 22.10.2024 17:15:04
 - Last modified 25.10.2024 19:10:08
 
Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action = add/edit and in (b) file admin.php under action = adduser/edituser.
CVE-2024-46240
- EPSS 0.09%
 - Published 22.10.2024 16:15:07
 - Last modified 25.10.2024 19:00:20
 
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under action=system and the company/contact parameters under action=addcust within admin.php file.
CVE-2021-3298
- EPSS 0.16%
 - Published 29.01.2021 06:15:13
 - Last modified 21.11.2024 06:21:14
 
Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter.
CVE-2020-13655
- EPSS 0.36%
 - Published 31.08.2020 15:15:10
 - Last modified 21.11.2024 05:01:41
 
An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is set to movefile and the id parameter corresponds to a project the current user has access to, the file and target parameters are re...
CVE-2015-0258
- EPSS 16.5%
 - Published 17.02.2020 18:15:11
 - Last modified 21.11.2024 02:22:40
 
Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2) .php4, (3) .php5, or (4) ...
CVE-2013-5027
- EPSS 0.36%
 - Published 27.12.2019 18:15:10
 - Last modified 21.11.2024 01:56:55
 
Collabtive 1.0 has incorrect access control
CVE-2019-8935
- EPSS 0.21%
 - Published 19.02.2019 15:29:00
 - Last modified 21.11.2024 04:50:41
 
Collabtive 3.1 allows XSS via the manageuser.php?action=profile id parameter.
CVE-2014-3247
- EPSS 0.8%
 - Published 15.05.2014 14:55:07
 - Last modified 12.04.2025 10:46:40
 
Cross-site scripting (XSS) vulnerability in Collabtive 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the desc parameter in an Add project (addpro) action to admin.php.