dootask dootask CVE Vulnerabilities (4)

CVEs: 4 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting dootask dootask (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-29828 DooTask v1.6.27 has a Cross-Site Scripting (XSS) vulnerability in the /manage/project/<id> page via the input field projectDesc. [email protected] 6.1 0.15% 2026-03-20 2026-04-02
CVE-2025-55455 DooTask v1.0.51 was dicovered to contain an authenticated arbitrary download vulnerability via the component /msg/sendtext. [email protected] 3.5 0.26% 2025-08-22 2025-09-12
CVE-2025-55454 An authenticated arbitrary file upload vulnerability in the component /msg/sendfiles of DooTask v1.0.51 allows attackers to execute arbitrary code via uploading a crafted file. [email protected] 8.8 0.61% 2025-08-22 2025-09-12
CVE-2024-34906 An arbitrary file upload vulnerability in dootask v0.30.13 allows attackers to execute arbitrary code via uploading a crafted PDF file. [email protected] 5.4 0.40% 2024-05-15 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence