Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2727▼ 85 respecto a la semana anterior
Críticas / altas1416▲ 186 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.45% | — | Code-projects Task ManagerAI | 21/3/2026 | 17/6/2026 | The Task Manager plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'search' AJAX action in all versions up to, and including, 3.0.2. This is due to missing capability checks in the callback_search() function and insufficient input validation that allows shortcode syntax (square brackets) to… | |
| Aplazada | Media (6.5) | 0.25% | — | Code-projects Task ManagerAI | 21/3/2026 | 17/6/2026 | The Task Manager plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.0.2 via the callback_get_text_from_url() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which… | |
| Aplazada | Alta (7.5) | 0.46% | — | Code-projects Task ManagerAI | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Agence web Eoxia – Montpellier Task Manager task-manager allows PHP Local File Inclusion.This issue affects Task Manager: from n/a through <= 3.0.2. | |
| Aplazada | Alta (7.1) | 0.26% | — | Pshikli Accessibility Task ManagerAI | 23/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pshikli Accessibility Task Manager accessibility-task-manager allows Reflected XSS.This issue affects Accessibility Task Manager: from n/a through <= 1.2.1. | |
| Analizada | Media (5.3) | 0.46% | — | Code-projects Task Manager | 12/11/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Task Manager 1.0. This affects an unknown part of the file /newProject.php. The manipulation of the argument projectName leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and… | |
| Modificada | Media (6.1) | 0.36% | — | Remyandrade School Task Manager | 14/5/2024 | 17/6/2026 | In Sourcecodester School Task Manager v1.0, a vulnerability was identified within the subject_name= parameter, enabling Stored Cross-Site Scripting (XSS) attacks. This vulnerability allows attackers to manipulate the subject's name, potentially leading to the execution of malicious JavaScript payloads. | |
| Analizada | Media (6.1) | 0.29% | — | Rems School Task Manager | 14/5/2024 | 17/6/2026 | Sourcecodester School Task Manager 1.0 is vulnerable to Cross Site Scripting (XSS) via add-task.php?task_name=. | |
| Analizada | Crítica (9.1) | 0.80% | — | Rems School Task Manager | 14/5/2024 | 17/6/2026 | SQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the delete-task.php component. | |
| Analizada | Crítica (9.8) | 0.75% | — | Code-projects Task Manager | 14/2/2024 | 17/6/2026 | Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID parameter at /TaskManager/EditProject.php. | |
| Analizada | Media (6.1) | 0.41% | — | Code-projects Task Manager | 14/2/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Note Section parameter at /TaskManager/Tasks.php. | |
| Analizada | Crítica (9.8) | 0.68% | — | Code-projects Task Manager | 14/2/2024 | 17/6/2026 | Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the taskID parameter at /TaskManager/EditTask.php. | |
| Analizada | Media (6.1) | 0.46% | — | Code-projects Task Manager | 14/2/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Task Name parameter /TaskManager/Task.php. | |
| Analizada | Media (6.1) | 0.41% | — | Code-projects Task Manager | 14/2/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Project Name parameter /TaskManager/Projects.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Rems School Task Manager | 13/2/2024 | 17/6/2026 | Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter. | |
| Modificada | Crítica (9.8) | 1.1% | — | Remyandrade School Task Manager | 29/1/2024 | 17/6/2026 | Sourcecodester School Task Manager App 1.0 allows SQL Injection via the 'task' parameter. |