Products: 2
Vulnerabilities: 3
Known Exploited: 0
0
Critical Level Threats
1
High Level Threats
2
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-10285
DevaslanPHP project-management Ticket KanbanScrumHelper.php recordUpdated improper authorization
Last Modified: Jun 02, 2026
Published: Jun 01, 2026
CVE-2026-10284
DevaslanPHP project-management Livewire ViewTicket.php doDeleteComment improper authorization
Last Modified: Jun 03, 2026
Published: Jun 01, 2026
CVE-2025-52203
A stored cross-site scripting (XSS) vulnerability exists in DevaslanPHP project-management v1.2.4. The vulnerability resides in the Ticket Name field, which fails to properly sanitize user-supplied input. An authenticated attacker can inject malicious JavaScript payloads into this field, which are subsequently stored in the database. When a legitimate user logs in and is redirected to the Dashboard panel "automatically upon authentication the malicious script executes in the user's browser context.
Last Modified: Aug 06, 2025
Published: Jul 31, 2025
Items Per Page
