VendorsAnukotime_trackerany version
Vulnerabilities

Anuko Time Tracker any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2020-27422
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.
Published 2020-11-16 · Modified
9.81 PoCEPSS 0.079
CVE-2023-32306
Time Tracker has Blind SQL Injection Vulnerability in Reports
Published 2023-05-12 · Modified
9.8EPSS 0.007
CVE-2023-32308
SQL Injection Vulnerability in anuko timetracker
Published 2023-05-15 · Modified
9.8EPSS 0.007
CVE-2021-21352
Predictable tokens used for password resets
Published 2021-03-03 · Modified
9.1EPSS 0.015
CVE-2022-24707
SQL injection in anuko timetracker
Published 2022-02-23 · Modified
8.81 PoCEPSS 0.072
CVE-2021-43851
SQL injection vulnerability in anuko timetracker
Published 2021-12-21 · Modified
8.8EPSS 0.012
CVE-2020-15255
CSV injection in Anuko Time Tracker
Published 2020-10-16 · Modified
8.71 PoCEPSS 0.035
CVE-2021-41139
Reflected XSS vulnerability in time.php
Published 2021-10-13 · Modified
8.1EPSS 0.010
CVE-2021-29436
Cross site request forgery vulnerability
Published 2021-04-13 · Modified
8.1EPSS 0.005
CVE-2020-27423
Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox
Published 2020-11-16 · Modified
7.51 PoCEPSS 0.064
CVE-2022-24708
Stored XSS vulnerability in anuko/timetracker
Published 2022-02-23 · Modified
6.5EPSS 0.006
CVE-2023-32066
Time Tracker has Stored XSS vulnerability in Week View plugin
Published 2023-05-09 · Modified
5.4EPSS 0.004