Vulnerabilities (CVE)

Filtered by vendor Webtareas Project Subscribe
Filtered by product Webtareas
Total 25 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-25734 1 Webtareas Project 1 Webtareas 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
webTareas through 2.1 allows files/Default/ Directory Listing.
CVE-2020-25733 1 Webtareas Project 1 Webtareas 2024-11-21 5.0 MEDIUM 7.5 HIGH
webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types.
CVE-2020-23660 1 Webtareas Project 1 Webtareas 2024-11-21 3.5 LOW 5.4 MEDIUM
webTareas v2.1 is affected by Cross Site Scripting (XSS) on "Search."
CVE-2020-23069 1 Webtareas Project 1 Webtareas 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a malicious user read arbitrary files.
CVE-2020-14973 1 Webtareas Project 1 Webtareas 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The loginForm within the general/login.php webpage in webTareas 2.0p8 suffers from a Reflected Cross Site Scripting (XSS) vulnerability via the query string.