VendorswebTareas Projectwebtareas2.4
Vulnerabilities

webTareas Project webTareas 2.0 Patch 8 2.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2021-43481
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.
Published 2022-04-20 · Modified
9.81 PoCEPSS 0.056
CVE-2022-44290
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.
Published 2022-12-02 · Modified
9.8EPSS 0.037
CVE-2022-44291
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
Published 2022-12-02 · Modified
9.8EPSS 0.037
CVE-2023-53972
WebTareas 2.4 Unauthenticated SQL Injection via Session Cookie Parameter
Published 2025-12-22 · Modified
9.3EPSS 0.004
CVE-2023-53971
WebTareas 2.4 Authenticated Remote Code Execution via File Upload
Published 2025-12-22 · Analyzed
8.8EPSS 0.005
CVE-2022-44957
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /clients/listclients.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Published 2022-12-02 · Modified
5.4EPSS 0.011
CVE-2022-44953
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /linkedcontent/listfiles.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field after clicking "Add".
Published 2022-12-02 · Modified
5.4EPSS 0.004
CVE-2022-44954
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /contacts/listcontacts.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name field after clicking "Add".
Published 2022-12-02 · Modified
5.4EPSS 0.004
CVE-2022-44956
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /projects/listprojects.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Published 2022-12-02 · Modified
5.4EPSS 0.004
CVE-2022-44959
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /meetings/listmeetings.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Published 2022-12-02 · Modified
5.4EPSS 0.004
CVE-2022-44955
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the Chat function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Messages field.
Published 2022-12-02 · Modified
5.4EPSS 0.004
CVE-2022-44960
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /general/search.php?searchtype=simple. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search field.
Published 2022-12-02 · Modified
5.4EPSS 0.004
CVE-2022-44961
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /forums/editforum.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Published 2022-12-02 · Modified
5.4EPSS 0.004
CVE-2022-44962
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /calendar/viewcalendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Subject field.
Published 2022-12-02 · Modified
5.4EPSS 0.004