VendorsChuck24simple_to-do_list_systemall versions
Vulnerabilities

Chuck24 Simple To-Do List System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2025-4248
SourceCodester Simple To-Do List System complete_task.php sql injection
Published 2025-05-04 · Analyzed
9.8EPSS 0.005
CVE-2025-4247
SourceCodester Simple To-Do List System delete_task.php sql injection
Published 2025-05-04 · Analyzed
8.8EPSS 0.005
CVE-2025-10117
SourceCodester Simple To-Do List System Add New Task fetch_tasks.php cross site scripting
Published 2025-09-09 · Analyzed
5.4EPSS 0.003
CVE-2025-63709
A Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Simple To-Do List System 1.0 in the "Add Tasks" text input. An authenticated user can submit HTML/JavaScript that is not correctly sanitized or encoded on output. The injected script is stored and later rendered in the browser of any user who views the task, allowing execution of arbitrary script in the context of the victim's browser.
Published 2025-11-10 · Modified
5.4EPSS 0.002