Devaslanphp

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 3
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-10285

    DevaslanPHP project-management Ticket KanbanScrumHelper.php recordUpdated improper authorization

    Last Modified: Jun 02, 2026
    Published: Jun 01, 2026

    CVE-2026-10284

    DevaslanPHP project-management Livewire ViewTicket.php doDeleteComment improper authorization

    Last Modified: Jun 03, 2026
    Published: Jun 01, 2026

    CVE-2025-52203

    A stored cross-site scripting (XSS) vulnerability exists in DevaslanPHP project-management v1.2.4. The vulnerability resides in the Ticket Name field, which fails to properly sanitize user-supplied input. An authenticated attacker can inject malicious JavaScript payloads into this field, which are subsequently stored in the database. When a legitimate user logs in and is redirected to the Dashboard panel "automatically upon authentication the malicious script executes in the user's browser context.

    Last Modified: Aug 06, 2025
    Published: Jul 31, 2025
    Items Per Page
    Devaslanphp Vulnerabilities & Security CVEs | CVE-DB