Extension WordPress
Vulnérabilités Taskbuilder – Project Management & Task Management Tool With Kanban Board
Cette page rassemble les failles publiées pour Taskbuilder – Project Management & Task Management Tool With Kanban Board, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Taskbuilder – Project Management & Task Management Tool With Kanban Board
15 fiches
Taskbuilder <= 5.0.8 – Authenticated (Subscriber+) SQL Injection via 'task_search' Parameter
The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to generic SQL Injection via the 'task_search' parameter in all versions up to, and including, 5.0.8 due to insufficient escaping on…
*-5.0.8
5.0.9
30/06/2026
Taskbuilder <= 5.0.8 – Authenticated (Subscriber+) SQL Injection via 'wppm_proj_filter' Parameter
The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to generic SQL Injection via the 'wppm_proj_filter' parameter in all versions up to, and including, 5.0.8 due to insufficient escaping on…
*-5.0.8
5.0.9
30/06/2026
Taskbuilder – Project Management & Task Management Tool With Kanban Board <= 5.0.7 – Authenticated (Subscriber+) SQL Injection
The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.0.7 due to insufficient escaping on the user supplied parameter and lack…
*-5.0.7
5.0.8
10/06/2026
Taskbuilder – Project Management & Task Management Tool With Kanban Board <= 5.0.6 – Authenticated (Subscriber+) Time-Based Blind SQL Injection via 'project_search' Parameter
The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'project_search' parameter in all versions up to, and including, 5.0.6 due to insufficient escaping…
*-5.0.6
5.0.7
13/05/2026
Taskbuilder <= 5.0.3 – Authenticated (Administrator+) Stored Cross-Site Scripting via 'Block Emails' Field
The Taskbuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-5.0.3
5.0.4
03/03/2026
Taskbuilder <= 5.0.2 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Project/Task Comment Creation
The Taskbuilder – WordPress Project Management & Task Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.0.2. This is due to missing authorization checks on the project and task comment…
*-5.0.2
5.0.3
17/02/2026
Taskbuilder <= 5.0.2 – Authenticated (Subscriber+) SQL Injection via 'order' and 'sort_by' Parameters
The Taskbuilder – WordPress Project Management & Task Management plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order' and 'sort_by' parameters in all versions up to, and including, 5.0.2 due to insufficient escaping on…
*-5.0.2
5.0.3
17/02/2026
Taskbuilder <= 4.0.9 – Reflected Cross-Site Scripting
The Taskbuilder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-4.0.9
5.0.0
06/01/2026
Taskbuilder <= 4.0.7 – Missing Authorization
The Taskbuilder – WordPress Project & Task Management plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.0.7. This makes it possible…
*-4.0.7
4.0.8
05/06/2025
Taskbuilder <= 4.0.1 – Authenticated (Subscriber+) SQL Injection
The Taskbuilder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-4.0.1
4.0.2
17/04/2025
Taskbuilder <= 3.0.8 – Authenticated (Admin+) SQL Injection
The Taskbuilder – WordPress Project & Task Management plugin plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient…
*-3.0.8
3.0.9
03/03/2025
Taskbuilder <= 3.0.6 – Authenticated (Subscriber+) SQL Injection
The Taskbuilder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-3.0.6
3.0.7
15/01/2025
Taskbuilder – WordPress Project & Task Management plugin <= 3.0.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via wppm_tasks Shortcode
The Taskbuilder – WordPress Project & Task Management plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppm_tasks shortcode in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output…
*-3.0.6
3.0.7
03/01/2025
Taskbuilder – WordPress Project & Task Management plugin <= 3.0.4 – Authenticated (Admin+) SQL injection
The Taskbuilder – WordPress Project & Task Management plugin plugin for WordPress is vulnerable to SQL Injection via the 'load_orders' parameter in all versions up to, and including, 3.0.4 due to insufficient escaping on the user supplied parameter…
*-3.0.4
3.0.5
31/10/2024
Taskbuilder <= 1.0.7 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The Taskbuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-1.0.7
1.0.8
15/09/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.