VendorsFairsketchrise_ultimate_project_managerall versions
Vulnerabilities

Fairsketch Rise Ultimate Project Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2017-17999
SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL commands via the search parameter to index.php/knowledge_base/get_article_suggestion/.
Published 2018-01-23 · Modified
9.81 PoCEPSS 0.033
CVE-2024-8945
CodeCanyon RISE Ultimate Project Manager save sql injection
Published 2024-09-17 · Analyzed
8.81 PoCEPSS 0.160
CVE-2025-60378
Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into invoices and messages. Injected content renders in emails, PDFs, and messaging/chat modules sent to clients or team members, enabling phishing, credential theft, and business email compromise. Automated recurring invoices and messaging amplify the risk by distributing malicious content to multiple recipients.
Published 2025-10-10 · Modified
8.1EPSS 0.011
CVE-2024-0545
CodeCanyon RISE Ultimate Project Manager signin redirect
Published 2024-01-15 · Modified
6.9EPSS 0.005
CVE-2025-63293
FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user can append comments or upload attachments to tickets for which they lack view or edit authorization, due to missing authorization checks in the ticketing/commenting API.
Published 2025-11-03 · Modified
6.5EPSS 0.004
CVE-2025-56807
A cross-site scripting (XSS) vulnerability in FairSketch RISE Ultimate Project Manager & CRM 3.9.4 allows an administrator to store a JavaScript payload using the file explorer in the admin dashboard when creating new folders.
Published 2025-09-29 · Modified
6.1EPSS 0.002
CVE-2017-11182
In Rise Ultimate Project Manager v1.8, XSS vulnerabilities were found in the My Profile section. All input fields are vulnerable.
Published 2017-07-12 · Modified
5.4EPSS 0.008
CVE-2017-11181
In Rise Ultimate Project Manager v1.8, XSS vulnerabilities were found in the Messaging section. Subject and Message fields are vulnerable.
Published 2017-07-12 · Modified
5.4EPSS 0.007
CVE-2025-41106
Multiple vulnerabilities in Fairsketch's RISE CRM Framework
Published 2025-11-11 · Analyzed
5.4EPSS 0.002
CVE-2025-41101
Multiple vulnerabilities in Fairsketch's RISE CRM Framework
Published 2025-11-11 · Analyzed
5.4EPSS 0.002
CVE-2025-41102
Multiple vulnerabilities in Fairsketch's RISE CRM Framework
Published 2025-11-11 · Analyzed
5.4EPSS 0.002
CVE-2025-41103
Multiple vulnerabilities in Fairsketch's RISE CRM Framework
Published 2025-11-11 · Analyzed
5.4EPSS 0.002
CVE-2025-41104
Multiple vulnerabilities in Fairsketch's RISE CRM Framework
Published 2025-11-11 · Analyzed
5.4EPSS 0.002
CVE-2025-41105
Multiple vulnerabilities in Fairsketch's RISE CRM Framework
Published 2025-11-11 · Analyzed
5.4EPSS 0.002
CVE-2025-3855
CodeCanyon RISE Ultimate Project Manager Profile Picture save_profile_image resource injection
Published 2025-04-22 · Analyzed
5.3EPSS 0.005