Bdtask records
37 published records for vendor bdtask.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
- CWE-352 Cross-Site Request Forgery (CSRF)7
- CWE-284 Improper Access Control4
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')3
- CWE-840 Business Logic Errors3
- CWE-285 Improper Authorization2
The weakness classes this vendor ships most often: where to look.
CWEAll records
37 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-28993No exploit | Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request.bdtask · multi store inventory management system · CWE-862 | Critical9.8 | — | 1.7% | May 20, 2022 |
36Monitor | CVE-2024-2317No exploit | Bdtask Hospital AutoManager Prescription Page improper authorizationbdtask · hospital automanager · CWE-285 | Critical9.1 | — | 0.8% | Mar 8, 2024 |
30Monitor | CVE-2022-28991No exploit | Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to accbdtask · multi store inventory management system · CWE-425 | High7.5 | — | 1.5% | May 20, 2022 |
28Monitor | CVE-2019-25505No exploit | Tradebox 5.4 SQL Injection via symbol Parameterbdtask · tradebox · CWE-89 | High7.1 | — | 0.3% | Mar 4, 2026 |
26Monitor | CVE-2020-13426No exploit | The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it presents, allowing the bdtask · multi-scheduler · CWE-352 | Medium6.5 | — | 1.2% | Jun 22, 2020 |
26Monitor | CVE-2024-2134No exploit | Bdtask Hospita AutoManager Investigation Report cross-site request forgerybdtask · hospital automanager · CWE-352 | Medium6.5 | — | 0.4% | Mar 2, 2024 |
24Monitor | CVE-2024-2135No exploit | Bdtask Hospita AutoManager Hospital Activities Page form cross site scriptingbdtask · hospital automanager · CWE-79 | Medium6.1 | — | 0.5% | Mar 2, 2024 |
24Monitor | CVE-2024-2276No exploit | Bdtask G-Prescription Gynaecology & OBS Consultation Software Edit Venue Page cross site scriptingbdtask · g-prescription gynaecology \& obs consultation · CWE-79 | Medium6.1 | — | 0.5% | Mar 7, 2024 |
24Monitor | CVE-2024-2274No exploit | Bdtask G-Prescription Gynaecology & OBS Consultation Software Prescription Dashboard Index cross site scriptingbdtask · g-prescription gynaecology \& obs consultation · CWE-79 | Medium6.1 | — | 0.5% | Mar 7, 2024 |
24Monitor | CVE-2024-2275No exploit | Bdtask G-Prescription Gynaecology & OBS Consultation Software OBS Patient/Gynee Prescription cross site scriptingbdtask · g-prescription gynaecology \& obs consultation · CWE-79 | Medium6.1 | — | 0.5% | Mar 7, 2024 |
21Monitor | CVE-2024-2997Proof of concept | Bdtask Multi-Store Inventory Management System cross site scriptingbdtask · multi store inventory management system · CWE-79 | Medium5.4 | — | 1.2% | Mar 27, 2024 |
21Monitor | CVE-2024-2998No exploit | Bdtask Multi-Store Inventory Management System Store Update Page cross site scriptingbdtask · multi store inventory management system · CWE-79 | Medium5.4 | — | 0.5% | Mar 27, 2024 |
20Monitor | CVE-2021-47769No exploit | Isshue Shopping Cart 3.5 - 'Title' Cross Site Scripting (XSS)bdtask · isshue · CWE-79 | Medium5.1 | — | 0.3% | Jan 15, 2026 |
19Monitor | CVE-2020-36012No exploit | Stored XSS vulnerability in BDTASK Multi-Store Inventory Management System 1.0 allows a local admin to inject arbitrary code via the Customebdtask · multi-store · CWE-79 | Medium4.8 | — | 0.6% | Jan 27, 2021 |
19Monitor | CVE-2024-2996No exploit | Bdtask Multi-Store Inventory Management System Page Title cross site scriptingbdtask · multi store inventory management system · CWE-79 | Medium4.8 | — | 0.5% | Mar 27, 2024 |
19Monitor | CVE-2024-1749No exploit | Bdtask Bhojon Best Restaurant Management Software Message Page message cross site scriptingbdtask · bhojon · CWE-79 | Medium4.8 | — | 0.5% | Feb 22, 2024 |
17Monitor | CVE-2024-2639No exploit | Bdtask Wholesale Inventory Management System session fixiationbdtask · wholesale inventory management system · CWE-384 | Medium4.3 | — | 0.5% | Mar 19, 2024 |
17Monitor | CVE-2024-3151No exploit | Bdtask Multi-Store Inventory Management System Stock Movement Page cross-site request forgerybdtask · m-store · CWE-352 | Medium4.3 | — | 0.4% | Apr 2, 2024 |
17Monitor | CVE-2024-2316No exploit | Bdtask Hospital AutoManager Update Bill Page cross-site request forgerybdtask · hospital automanager · CWE-352 | Medium4.3 | — | 0.4% | Mar 8, 2024 |
17Monitor | CVE-2024-2277No exploit | Bdtask G-Prescription Gynaecology & OBS Consultation Software Password Reset change_password_save cross-site request forgerybdtask · g-prescription gynaecology \& obs consultation · CWE-352 | Medium4.3 | — | 0.3% | Mar 7, 2024 |
9Monitor | CVE-2024-2133No exploit | Bdtask Isshue Multi Store eCommerce Shopping Cart Solution Manage Sale Page manage_invoice cross site scriptingbdtask · isshue multi store ecommerce shopping cart solution · CWE-79 | Low2.4 | — | 0.5% | Mar 2, 2024 |
8Monitor | CVE-2025-12288No exploit | Bdtask Pharmacy Management System User Profile edit_user authorizationbdtask · pharmacare · CWE-285 | Low2.1 | — | 0.5% | Oct 27, 2025 |
8Monitor | CVE-2025-12287No exploit | Bdtask Wholesale Inventory Control and Inventory Management System edit_profile sql injectionbdtask · wholesale · CWE-74 | Low2.0 | — | 0.5% | Oct 27, 2025 |
8Monitor | CVE-2025-12222No exploit | Bdtask Flight Booking Software Deposit deposit unrestricted uploadbdtask · flight booking software · CWE-284 | Low2.1 | — | 0.4% | Oct 27, 2025 |
8Monitor | CVE-2025-12223No exploit | Bdtask Flight Booking Software Package Information package-information unrestricted uploadbdtask · flight booking software · CWE-284 | Low2.1 | — | 0.4% | Oct 27, 2025 |
- CVE-2022-2899339Monitor
Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request.
CriticalCVSS 9.8No exploitEPSS 2%bdtask · multi store inventory management systemMay 20, 2022
- CVE-2024-231736Monitor
Bdtask Hospital AutoManager Prescription Page improper authorization
CriticalCVSS 9.1No exploitEPSS 1%bdtask · hospital automanagerMar 8, 2024
- CVE-2022-2899130Monitor
Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to acc
HighCVSS 7.5No exploitEPSS 1%bdtask · multi store inventory management systemMay 20, 2022
- CVE-2019-2550528Monitor
Tradebox 5.4 SQL Injection via symbol Parameter
HighCVSS 7.1No exploitEPSS 0%bdtask · tradeboxMar 4, 2026
- CVE-2020-1342626Monitor
The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it presents, allowing the
MediumCVSS 6.5No exploitEPSS 1%bdtask · multi-schedulerJun 22, 2020
- CVE-2024-213426Monitor
Bdtask Hospita AutoManager Investigation Report cross-site request forgery
MediumCVSS 6.5No exploitEPSS 0%bdtask · hospital automanagerMar 2, 2024
- CVE-2024-213524Monitor
Bdtask Hospita AutoManager Hospital Activities Page form cross site scripting
MediumCVSS 6.1No exploitEPSS 1%bdtask · hospital automanagerMar 2, 2024
- CVE-2024-227624Monitor
Bdtask G-Prescription Gynaecology & OBS Consultation Software Edit Venue Page cross site scripting
MediumCVSS 6.1No exploitEPSS 0%bdtask · g-prescription gynaecology \& obs consultationMar 7, 2024
- CVE-2024-227424Monitor
Bdtask G-Prescription Gynaecology & OBS Consultation Software Prescription Dashboard Index cross site scripting
MediumCVSS 6.1No exploitEPSS 0%bdtask · g-prescription gynaecology \& obs consultationMar 7, 2024
- CVE-2024-227524Monitor
Bdtask G-Prescription Gynaecology & OBS Consultation Software OBS Patient/Gynee Prescription cross site scripting
MediumCVSS 6.1No exploitEPSS 0%bdtask · g-prescription gynaecology \& obs consultationMar 7, 2024
- CVE-2024-299721Monitor
Bdtask Multi-Store Inventory Management System cross site scripting
MediumCVSS 5.4Proof of conceptEPSS 1%bdtask · multi store inventory management systemMar 27, 2024
- CVE-2024-299821Monitor
Bdtask Multi-Store Inventory Management System Store Update Page cross site scripting
MediumCVSS 5.4No exploitEPSS 1%bdtask · multi store inventory management systemMar 27, 2024
- CVE-2021-4776920Monitor
Isshue Shopping Cart 3.5 - 'Title' Cross Site Scripting (XSS)
MediumCVSS 5.1No exploitEPSS 0%bdtask · isshueJan 15, 2026
- CVE-2020-3601219Monitor
Stored XSS vulnerability in BDTASK Multi-Store Inventory Management System 1.0 allows a local admin to inject arbitrary code via the Custome
MediumCVSS 4.8No exploitEPSS 1%bdtask · multi-storeJan 27, 2021
- CVE-2024-299619Monitor
Bdtask Multi-Store Inventory Management System Page Title cross site scripting
MediumCVSS 4.8No exploitEPSS 1%bdtask · multi store inventory management systemMar 27, 2024
- CVE-2024-174919Monitor
Bdtask Bhojon Best Restaurant Management Software Message Page message cross site scripting
MediumCVSS 4.8No exploitEPSS 0%bdtask · bhojonFeb 22, 2024
- CVE-2024-263917Monitor
Bdtask Wholesale Inventory Management System session fixiation
MediumCVSS 4.3No exploitEPSS 1%bdtask · wholesale inventory management systemMar 19, 2024
- CVE-2024-315117Monitor
Bdtask Multi-Store Inventory Management System Stock Movement Page cross-site request forgery
MediumCVSS 4.3No exploitEPSS 0%bdtask · m-storeApr 2, 2024
- CVE-2024-231617Monitor
Bdtask Hospital AutoManager Update Bill Page cross-site request forgery
MediumCVSS 4.3No exploitEPSS 0%bdtask · hospital automanagerMar 8, 2024
- CVE-2024-227717Monitor
Bdtask G-Prescription Gynaecology & OBS Consultation Software Password Reset change_password_save cross-site request forgery
MediumCVSS 4.3No exploitEPSS 0%bdtask · g-prescription gynaecology \& obs consultationMar 7, 2024
- CVE-2024-21339Monitor
Bdtask Isshue Multi Store eCommerce Shopping Cart Solution Manage Sale Page manage_invoice cross site scripting
LowCVSS 2.4No exploitEPSS 0%bdtask · isshue multi store ecommerce shopping cart solutionMar 2, 2024
- CVE-2025-122888Monitor
Bdtask Pharmacy Management System User Profile edit_user authorization
LowCVSS 2.1No exploitEPSS 0%bdtask · pharmacareOct 27, 2025
- CVE-2025-122878Monitor
Bdtask Wholesale Inventory Control and Inventory Management System edit_profile sql injection
LowCVSS 2.0No exploitEPSS 0%bdtask · wholesaleOct 27, 2025
- CVE-2025-122228Monitor
Bdtask Flight Booking Software Deposit deposit unrestricted upload
LowCVSS 2.1No exploitEPSS 0%bdtask · flight booking softwareOct 27, 2025
- CVE-2025-122238Monitor
Bdtask Flight Booking Software Package Information package-information unrestricted upload
LowCVSS 2.1No exploitEPSS 0%bdtask · flight booking softwareOct 27, 2025