Extension WordPress

Vulnérabilités Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

Cette page rassemble les failles publiées pour Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker, leurs plages de versions affectées et les correctifs signalés dans la base locale.

22Vulnérabilités
0Critiques
22Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

22 fiches

CVE-2025-68040 Moyenne · 4,3
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

Project Manager <= 3.0.1 – Authenticated (Subscriber+) Information Exposure

The Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.1. This makes it possible for authenticated…

Versions affectées

*-3.0.1

Correctif

3.0.2

Publication

26/12/2025

CVE-2025-8994 Moyenne · 6,5
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

WP Project Manager <= 2.6.26 – Authenticated (Subscriber+) SQL Injection via 'completed_at_operator'

The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘completed_at_operator’ parameter in all versions up to, and including, 2.6.26…

Versions affectées

*-2.6.26

Correctif

2.6.27

Publication

14/11/2025

CVE-2025-58269 Moyenne · 5,3
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

WP Project Manager <= 2.6.25 – Unauthenticated Sensitive Information Exposure

The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.25. This makes it possible…

Versions affectées

*-2.6.25

Correctif

2.6.26

Publication

22/09/2025

CVE-2025-2541 Moyenne · 6,4
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

WP Project Manager <= 2.6.22 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-2.6.22

Correctif

2.6.23

Publication

11/04/2025

CVE-2025-3100 Moyenne · 6,4
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.22 – Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22…

Versions affectées

*-2.6.22

Correctif

2.6.23

Publication

08/04/2025

CVE-2025-32280 Moyenne · 4,3
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

WP Project Manager <= 2.6.24 – Cross-Site Request Forgery

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.24. This is due to…

Versions affectées

*-2.6.24

Correctif

2.6.25

Publication

04/04/2025

CVE-2024-13500 Moyenne · 6,5
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

WP Project Manager <= 2.6.17 – Authenticated (Subscriber+) SQL Injection via orderby Parameter

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.6.17…

Versions affectées

*-2.6.17

Correctif

2.6.18

Publication

15/02/2025

CVE-2024-13752 Moyenne · 6,5
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

WP Project Manager <= 2.6.17 – Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check in the '/pm/v2/settings/notice' endpoint all…

Versions affectées

*-2.6.17

Correctif

2.6.18

Publication

14/02/2025

CVE-2025-22649 Moyenne · 4,4
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

WP Project Manager <= 2.6.22 – Authenticated (Administrator+) Stored Cross-Site Scripting

The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access…

Versions affectées

*-2.6.22

Correctif

2.6.23

Publication

03/02/2025

CVE-2024-12195 Moyenne · 6,5
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.16 – Authenticated (Subscriber+) SQL Injection

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to SQL Injection via the 'project_id' parameter of the /wp-json/pm/v2/projects/2/task-lists REST API endpoint in all versions…

Versions affectées

*-2.6.16

Correctif

2.6.17

Publication

03/01/2025

CVE-2024-10548 Moyenne · 6,5
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

WP Project Manager <= 2.6.15 – Authenticated (Subscriber+) Sensitive Information Exposure via Project Task List REST API

The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Project Task List ('/wp-json/pm/v2/projects/1/task-lists') REST API endpoint. This makes it possible for authenticated attackers, with…

Versions affectées

*-2.6.15

Correctif

2.6.16

Publication

18/12/2024

CVE-2024-12015 Moyenne · 6,5
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

WP Project Manager <= 2.6.31 – Authenticated (Project Manager+) SQL Injection

The WP Project Manager plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in the '/pm/v2/activites' route in all versions up to, and including, 2.6.31 due to insufficient escaping on the user supplied parameter and…

Versions affectées

*-2.6.31

Correctif

3.0.0

Publication

02/12/2024

CVE-2024-10520 Moyenne · 5,3
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

WP Project Manager <= 2.6.14 – Missing Authorization to Project Milestone and Task Creation/Deletion

The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' method of the 'Create_Milestone', 'Create_Task_List', 'Create_Task', and 'Delete_Task' classes in version 2.6.14. This makes it…

Versions affectées

*-2.6.14

Correctif

2.6.15

Publication

19/11/2024

CVE-2024-10174 Élevée · 7,3
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.13 – Insecure Direct Object Reference to Unauthenticated Authorization Bypass

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.13 via the 'Abstract_Permission'…

Versions affectées

*-2.6.13

Correctif

2.6.14

Publication

12/11/2024

CVE-2023-49860 Moyenne · 6,4
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

WP Project Manager <= 2.6.8 – Authenticated (Subscriber+) Stored Cross-Site Scripting

The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access…

Versions affectées

*-2.6.8

Correctif

2.6.9

Publication

07/12/2023

CVE-2023-40003 Moyenne · 5,3
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

WP Project Manager <= 2.6.7 – Missing Authorization

The WP Project Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an unknown function in versions up to, and including, 2.6.7. This makes it possible for unauthenticated attackers to perform…

Versions affectées

*-2.6.7

Correctif

2.6.8

Publication

07/12/2023

CVE-2023-34383 Élevée · 8,8
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

WP Project Manager <= 2.6.0 – Authenticated (Subscriber+) SQL Injection

The WP Project Manager plugin for WordPress is vulnerable to SQL Injection via the user task starting date in versions up to, and including, 2.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient…

Versions affectées

*-2.6.0

Correctif

2.6.1

Publication

04/09/2023

CVE-2023-3636 Élevée · 8,8
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

WP Project Manager <= 2.6.4 – Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation

The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restriction on the 'save_users_map_name' function. This makes it possible for authenticated attackers, with minimal permissions such…

Versions affectées

*-2.6.4

Correctif

2.6.5

Publication

24/07/2023

Vulnérabilité Moyenne · 4,3
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

Appsero <= 1.2.1 – Missing Authorization

The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible…

Versions affectées

*-2.6.12

Correctif

2.6.13

Publication

16/12/2022

CVE-2022-47150 Moyenne · 4,3
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

Appsero <= 1.2.0 – Cross-Site Request Forgery

The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it…

Versions affectées

*-2.6.12

Correctif

2.6.13

Publication

14/12/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités