Filtered by vendor Webtareas Project Subscriptions
Total 25 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-44962 1 Webtareas Project 1 Webtareas 2024-08-03 5.4 Medium
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /calendar/viewcalendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Subject field.
CVE-2022-44956 1 Webtareas Project 1 Webtareas 2024-08-03 5.4 Medium
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /projects/listprojects.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
CVE-2022-44961 1 Webtareas Project 1 Webtareas 2024-08-03 5.4 Medium
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /forums/editforum.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
CVE-2022-44290 1 Webtareas Project 1 Webtareas 2024-08-03 9.8 Critical
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.
CVE-2022-44291 1 Webtareas Project 1 Webtareas 2024-08-03 9.8 Critical
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.