dootask CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

dootask vulnerability overview

Aggregates CVE and security vulnerability intelligence across all dootask-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk cross-site scripting; exposure may include vendor impact session compromise in vendor surface software deployment and vendor surface production workloads contexts.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-29828 DooTask v1.6.27 has a Cross-Site Scripting (XSS) vulnerability in the /manage/project/<id> page via the input field projectDesc. [email protected] 6.1 0.02% 2026-03-20 2026-04-02
CVE-2025-55455 DooTask v1.0.51 was dicovered to contain an authenticated arbitrary download vulnerability via the component /msg/sendtext. [email protected] 3.5 0.05% 2025-08-22 2025-09-12
CVE-2025-55454 An authenticated arbitrary file upload vulnerability in the component /msg/sendfiles of DooTask v1.0.51 allows attackers to execute arbitrary code via uploading a crafted file. [email protected] 8.8 0.27% 2025-08-22 2025-09-12
CVE-2024-34906 An arbitrary file upload vulnerability in dootask v0.30.13 allows attackers to execute arbitrary code via uploading a crafted PDF file. [email protected] 5.4 0.17% 2024-05-15 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence