Qdpm records
18 published records for vendor qdpm.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 11.1%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
60This week | CVE-2020-7246Weaponized | A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier.qdpm · qdpm · CWE-22 | High8.8 | — | 83.2% | Jan 21, 2020 |
40Plan | CVE-2020-11811No exploit | In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted contenqdpm · qdpm · CWE-434 | Critical9.8 | — | 3.0% | Apr 16, 2020 |
39Monitor | CVE-2015-3884Weaponized | Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) schqdpm · qdpm · CWE-434 | High8.8 | — | 14.4% | Mar 17, 2017 |
39Monitor | CVE-2023-45856No exploit | qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.qdpm · qdpm · CWE-434 | Critical9.8 | — | 1.4% | Oct 14, 2023 |
36Monitor | CVE-2022-26180Proof of concept | qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.qdpm · qdpm · CWE-352 | High8.8 | — | 3.8% | Apr 8, 2022 |
36Monitor | CVE-2020-26165No exploit | qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.classqdpm · qdpm · CWE-502 | High8.8 | — | 2.5% | Dec 31, 2020 |
35Monitor | CVE-2018-25208No exploit | qdPM 9.1 SQL Injection via filter_by Parametersqdpm · qdpm · CWE-89 | High8.8 | — | 0.3% | Mar 26, 2026 |
35Monitor | CVE-2019-25669No exploit | qdPM 9.1 SQL Injection via search_by_extrafields Parameterqdpm · qdpm · CWE-89 | High8.8 | — | 0.3% | Apr 5, 2026 |
31Monitor | CVE-2023-45855Proof of concept | qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.qdpm · qdpm · CWE-22 | High7.5 | — | 3.3% | Oct 14, 2023 |
30Monitor | CVE-2015-3881No exploit | Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to (1) core/config/datqdpm · qdpm · CWE-200 | High7.5 | — | 1.5% | Mar 17, 2017 |
27Monitor | CVE-2019-8390Proof of concept | qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.qdpm · qdpm · CWE-79 | Medium6.1 | — | 9.8% | May 14, 2019 |
25Monitor | CVE-2019-8391Proof of concept | qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter.qdpm · qdpm · CWE-79 | Medium6.1 | — | 3.3% | May 14, 2019 |
25Monitor | CVE-2020-19515Proof of concept | qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php.qdpm · qdpm · CWE-79 | Medium6.1 | — | 1.8% | Sep 9, 2021 |
24Monitor | CVE-2015-3883No exploit | Multiple cross-site scripting (XSS) vulnerabilities in qdPM 8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) seqdpm · qdpm · CWE-79 | Medium6.1 | — | 0.8% | Mar 17, 2017 |
21Monitor | CVE-2015-3882No exploit | qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], which reveals the insqdpm · qdpm · CWE-200 | Medium5.3 | — | 1.2% | Mar 17, 2017 |
21Monitor | CVE-2020-11814No exploit | A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users to malicious websiteqdpm · qdpm · CWE-74 | Medium5.4 | — | 1.0% | Apr 16, 2020 |
21Monitor | CVE-2020-26166No exploit | The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to inject web scriqdpm · qdpm · CWE-79 | Medium5.4 | — | 0.8% | Oct 5, 2020 |
21Monitor | CVE-2020-18468No exploit | Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a cqdpm · qdpm · CWE-79 | Medium5.4 | — | 0.4% | Aug 26, 2021 |
- CVE-2020-724660This week
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier.
HighCVSS 8.8WeaponizedEPSS 83%qdpm · qdpmJan 21, 2020
- CVE-2020-1181140Plan
In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted conten
CriticalCVSS 9.8No exploitEPSS 3%qdpm · qdpmApr 16, 2020
- CVE-2015-388439Monitor
Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) sch
HighCVSS 8.8WeaponizedEPSS 14%qdpm · qdpmMar 17, 2017
- CVE-2023-4585639Monitor
qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.
CriticalCVSS 9.8No exploitEPSS 1%qdpm · qdpmOct 14, 2023
- CVE-2022-2618036Monitor
qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.
HighCVSS 8.8Proof of conceptEPSS 4%qdpm · qdpmApr 8, 2022
- CVE-2020-2616536Monitor
qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class
HighCVSS 8.8No exploitEPSS 3%qdpm · qdpmDec 31, 2020
- CVE-2018-2520835Monitor
qdPM 9.1 SQL Injection via filter_by Parameters
HighCVSS 8.8No exploitEPSS 0%qdpm · qdpmMar 26, 2026
- CVE-2019-2566935Monitor
qdPM 9.1 SQL Injection via search_by_extrafields Parameter
HighCVSS 8.8No exploitEPSS 0%qdpm · qdpmApr 5, 2026
- CVE-2023-4585531Monitor
qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.
HighCVSS 7.5Proof of conceptEPSS 3%qdpm · qdpmOct 14, 2023
- CVE-2015-388130Monitor
Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to (1) core/config/dat
HighCVSS 7.5No exploitEPSS 2%qdpm · qdpmMar 17, 2017
- CVE-2019-839027Monitor
qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.
MediumCVSS 6.1Proof of conceptEPSS 10%qdpm · qdpmMay 14, 2019
- CVE-2019-839125Monitor
qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter.
MediumCVSS 6.1Proof of conceptEPSS 3%qdpm · qdpmMay 14, 2019
- CVE-2020-1951525Monitor
qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php.
MediumCVSS 6.1Proof of conceptEPSS 2%qdpm · qdpmSep 9, 2021
- CVE-2015-388324Monitor
Multiple cross-site scripting (XSS) vulnerabilities in qdPM 8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) se
MediumCVSS 6.1No exploitEPSS 1%qdpm · qdpmMar 17, 2017
- CVE-2015-388221Monitor
qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], which reveals the ins
MediumCVSS 5.3No exploitEPSS 1%qdpm · qdpmMar 17, 2017
- CVE-2020-1181421Monitor
A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users to malicious website
MediumCVSS 5.4No exploitEPSS 1%qdpm · qdpmApr 16, 2020
- CVE-2020-2616621Monitor
The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to inject web scri
MediumCVSS 5.4No exploitEPSS 1%qdpm · qdpmOct 5, 2020
- CVE-2020-1846821Monitor
Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a c
MediumCVSS 5.4No exploitEPSS 0%qdpm · qdpmAug 26, 2021