Extension WordPress
Vulnérabilités Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker
Cette page rassemble les failles publiées pour Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker
22 fiches
Project Manager <= 3.0.1 – Authenticated (Subscriber+) Information Exposure
The Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.1. This makes it possible for authenticated…
*-3.0.1
3.0.2
26/12/2025
WP Project Manager <= 2.6.26 – Authenticated (Subscriber+) SQL Injection via 'completed_at_operator'
The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘completed_at_operator’ parameter in all versions up to, and including, 2.6.26…
*-2.6.26
2.6.27
14/11/2025
WP Project Manager <= 2.6.25 – Unauthenticated Sensitive Information Exposure
The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.25. This makes it possible…
*-2.6.25
2.6.26
22/09/2025
WP Project Manager <= 2.6.22 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping. This makes it possible for…
*-2.6.22
2.6.23
11/04/2025
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.22 – Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22…
*-2.6.22
2.6.23
08/04/2025
WP Project Manager <= 2.6.24 – Cross-Site Request Forgery
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.24. This is due to…
*-2.6.24
2.6.25
04/04/2025
WP Project Manager <= 2.6.17 – Authenticated (Subscriber+) SQL Injection via orderby Parameter
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.6.17…
*-2.6.17
2.6.18
15/02/2025
WP Project Manager <= 2.6.17 – Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check in the '/pm/v2/settings/notice' endpoint all…
*-2.6.17
2.6.18
14/02/2025
WP Project Manager <= 2.6.22 – Authenticated (Administrator+) Stored Cross-Site Scripting
The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access…
*-2.6.22
2.6.23
03/02/2025
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.16 – Authenticated (Subscriber+) SQL Injection
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to SQL Injection via the 'project_id' parameter of the /wp-json/pm/v2/projects/2/task-lists REST API endpoint in all versions…
*-2.6.16
2.6.17
03/01/2025
WP Project Manager <= 2.6.15 – Authenticated (Subscriber+) Sensitive Information Exposure via Project Task List REST API
The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Project Task List ('/wp-json/pm/v2/projects/1/task-lists') REST API endpoint. This makes it possible for authenticated attackers, with…
*-2.6.15
2.6.16
18/12/2024
WP Project Manager <= 2.6.31 – Authenticated (Project Manager+) SQL Injection
The WP Project Manager plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in the '/pm/v2/activites' route in all versions up to, and including, 2.6.31 due to insufficient escaping on the user supplied parameter and…
*-2.6.31
3.0.0
02/12/2024
WP Project Manager <= 2.6.14 – Missing Authorization to Project Milestone and Task Creation/Deletion
The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' method of the 'Create_Milestone', 'Create_Task_List', 'Create_Task', and 'Delete_Task' classes in version 2.6.14. This makes it…
*-2.6.14
2.6.15
19/11/2024
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.13 – Insecure Direct Object Reference to Unauthenticated Authorization Bypass
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.13 via the 'Abstract_Permission'…
*-2.6.13
2.6.14
12/11/2024
WP Project Manager <= 2.6.8 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access…
*-2.6.8
2.6.9
07/12/2023
WP Project Manager <= 2.6.7 – Missing Authorization
The WP Project Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an unknown function in versions up to, and including, 2.6.7. This makes it possible for unauthenticated attackers to perform…
*-2.6.7
2.6.8
07/12/2023
WP Project Manager <= 2.6.0 – Authenticated (Subscriber+) SQL Injection
The WP Project Manager plugin for WordPress is vulnerable to SQL Injection via the user task starting date in versions up to, and including, 2.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient…
*-2.6.0
2.6.1
04/09/2023
WP Project Manager <= 2.6.4 – Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation
The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restriction on the 'save_users_map_name' function. This makes it possible for authenticated attackers, with minimal permissions such…
*-2.6.4
2.6.5
24/07/2023
Appsero <= 1.2.1 – Missing Authorization
The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible…
*-2.6.12
2.6.13
16/12/2022
Appsero <= 1.2.0 – Cross-Site Request Forgery
The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it…
*-2.6.12
2.6.13
14/12/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.