Webtareas Project
Webtareas Project Webtareas: vulnerabilidades y CVE
Webtareas Project Webtareas tiene 27 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE27
Últimos 12 meses2
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-53972 | Crítica (9.3) | 0.43% | — | 22 dic 2025 | WebTareas 2.4 contains a SQL injection vulnerability in the webTareasSID cookie parameter that allows unauthenticated attackers to manipulate database queries. Attackers can exploit error-based and time-based blind SQL… |
| CVE-2023-53971 | Alta (8.7) | 0.48% | — | 22 dic 2025 | WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functionality. Attackers can upload a PHP file with arbitrary code to the… |
| CVE-2022-44962 | Media (5.4) | 0.42% | — | 2 dic 2022 | webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /calendar/viewcalendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a… |
| CVE-2022-44961 | Media (5.4) | 0.42% | — | 2 dic 2022 | webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /forums/editforum.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted… |
| CVE-2022-44960 | Media (5.4) | 0.42% | — | 2 dic 2022 | webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /general/search.php?searchtype=simple. This vulnerability allows attackers to execute arbitrary web scripts or HTML… |
| CVE-2022-44959 | Media (5.4) | 0.43% | — | 2 dic 2022 | webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /meetings/listmeetings.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a… |
| CVE-2022-44957 | Media (5.4) | 1.1% | — | 2 dic 2022 | webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /clients/listclients.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted… |
| CVE-2022-44956 | Media (5.4) | 0.43% | — | 2 dic 2022 | webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /projects/listprojects.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a… |
| CVE-2022-44955 | Media (5.4) | 0.42% | — | 2 dic 2022 | webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the Chat function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into… |
| CVE-2022-44954 | Media (5.4) | 0.43% | — | 2 dic 2022 | webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /contacts/listcontacts.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a… |
| CVE-2022-44953 | Media (5.4) | 0.43% | — | 2 dic 2022 | webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /linkedcontent/listfiles.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a… |
| CVE-2022-44291 | Crítica (9.8) | 4.0% | — | 2 dic 2022 | webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php. |
| CVE-2022-44290 | Crítica (9.8) | 4.0% | — | 2 dic 2022 | webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php. |
| CVE-2021-36609 | Media (5.4) | 0.47% | — | 16 jun 2022 | Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /linkedcontent/editfolder.php. |
| CVE-2021-36608 | Media (5.4) | 0.47% | — | 16 jun 2022 | Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /projects/editproject.php. |
| CVE-2021-43481 | Crítica (9.8) | 5.6% | — | 20 abr 2022 | An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php. |
| CVE-2021-41920 | Alta (7.5) | 1.7% | — | 8 oct 2021 | webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor_champs, and sor_ordre HTTP POST… |
| CVE-2021-41919 | Alta (8.8) | 2.4% | — | 8 oct 2021 | webTareas version 2.4 and earlier allows an authenticated user to arbitrarily upload potentially dangerous files without restrictions. This is working by adding or replacing a personal profile picture. The affected… |
| CVE-2021-41918 | Media (5.4) | 0.56% | — | 8 oct 2021 | webTareas version 2.4 and earlier allows an authenticated user to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against the… |
| CVE-2021-41917 | Media (5.4) | 0.57% | — | 8 oct 2021 | webTareas version 2.4 and earlier allows an authenticated user to store arbitrary web script or HTML by creating or editing a client name in the clients section, due to incorrect sanitization of user-supplied data and… |
| CVE-2021-41916 | Alta (8.8) | 0.82% | — | 8 oct 2021 | A Cross-Site Request Forgery (CSRF) vulnerability in webTareas version 2.4 and earlier allows a remote attacker to create a new administrative profile and add a new user to the new profile. without the victim's… |
| CVE-2020-23069 | Media (6.5) | 1.6% | — | 18 ago 2021 | Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a malicious user read arbitrary files. |
| CVE-2020-25735 | Media (6.1) | 1.4% | — | 18 sept 2020 | webTareas through 2.1 allows XSS in clients/editclient.php, extensions/addextension.php, administration/add_announcement.php, administration/departments.php, administration/locations.php, expenses/claim_type.php,… |
| CVE-2020-25734 | Media (5.3) | 2.1% | — | 18 sept 2020 | webTareas through 2.1 allows files/Default/ Directory Listing. |
| CVE-2020-25733 | Alta (7.5) | 2.1% | — | 18 sept 2020 | webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types. |
| CVE-2020-23660 | Media (5.4) | 0.53% | — | 26 ago 2020 | webTareas v2.1 is affected by Cross Site Scripting (XSS) on "Search." |
| CVE-2020-14973 | Media (6.1) | 1.2% | — | 22 jun 2020 | The loginForm within the general/login.php webpage in webTareas 2.0p8 suffers from a Reflected Cross Site Scripting (XSS) vulnerability via the query string. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.