ProjectSend records
29 published records for vendor projectsend.
Researcher profile
- Entered KEV
- 1 · 3.4%
- Weaponized
- 2 · 6.9%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- 7 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-287 Improper Authentication2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File2
- CWE-330 Use of Insufficiently Random Values1
The weakness classes this vendor ships most often: where to look.
CWEAll records
29 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
97Now | CVE-2024-11680Weaponized | ProjectSend Unauthenticated Configuration Modificationprojectsend · projectsend · CWE-306 | Critical9.8 | KEV | 91.7% | Nov 26, 2024 |
43Plan | CVE-2014-9567Weaponized | Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows remote attackers to exeprojectsend · projectsend · CWE-94 | High7.5 | — | 43.3% | Jan 7, 2015 |
40Plan | CVE-2021-40887No exploit | Projectsend version r1295 is affected by a directory traversal vulnerability.projectsend · projectsend · CWE-22 | Critical9.8 | — | 2.4% | Oct 11, 2021 |
40Plan | CVE-2016-10733No exploit | ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string.projectsend · projectsend · CWE-22 | Critical9.8 | — | 2.1% | Oct 29, 2018 |
40Plan | CVE-2016-10732No exploit | ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or procprojectsend · projectsend · CWE-287 | Critical9.8 | — | 1.9% | Oct 29, 2018 |
39Monitor | CVE-2017-9741No exploit | install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to repprojectsend · projectsend · CWE-20 | Critical9.8 | — | 1.6% | Jun 18, 2017 |
39Monitor | CVE-2016-10734No exploit | ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.projectsend · projectsend · CWE-285 | Critical9.8 | — | 1.5% | Oct 29, 2018 |
39Monitor | CVE-2016-10731No exploit | ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the requprojectsend · projectsend · CWE-89 | Critical9.8 | — | 1.4% | Oct 29, 2018 |
36Monitor | CVE-2019-11378No exploit | An issue was discovered in ProjectSend r1053.projectsend · projectsend · CWE-22 | High8.8 | — | 3.6% | Apr 20, 2019 |
35Monitor | CVE-2018-7201No exploit | CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel.projectsend · projectsend · CWE-1236 | High8.8 | — | 1.3% | May 22, 2019 |
34Monitor | CVE-2023-53980No exploit | ProjectSend r1605 Remote Code Execution via File Extension Manipulationprojectsend · projectsend · CWE-434 | High8.7 | — | 0.9% | Dec 22, 2025 |
32Monitor | CVE-2021-40884No exploit | Projectsend version r1295 is affected by sensitive information disclosure.projectsend · projectsend · CWE-862 | High8.1 | — | 1.0% | Oct 11, 2021 |
31Monitor | CVE-2020-28874Proof of concept | reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic.projectsend · projectsend · CWE-287 | High7.5 | — | 2.4% | Jan 26, 2021 |
30Monitor | CVE-2019-11492No exploit | ProjectSend before r1070 writes user passwords to the server logs.projectsend · projectsend · CWE-532 | High7.5 | — | 1.1% | Apr 26, 2019 |
28Monitor | CVE-2023-53930No exploit | ProjectSend r1605 Insecure Direct Object Reference File Download Vulnerabilityprojectsend · projectsend · CWE-639 | High7.1 | — | 0.4% | Dec 17, 2025 |
27Monitor | CVE-2015-2564Proof of concept | SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to execute arbitrary SQprojectsend · projectsend · CWE-89 | Medium6.5 | — | 3.1% | Mar 20, 2015 |
27Monitor | CVE-2024-7658No exploit | projectsend process.php get_preview resource injectionprojectsend · projectsend · CWE-99 | Medium6.9 | — | 0.8% | Aug 12, 2024 |
26Monitor | CVE-2021-40886No exploit | Projectsend version r1295 is affected by a directory traversal vulnerability.projectsend · projectsend · CWE-22 | Medium6.5 | — | 1.4% | Oct 11, 2021 |
25Monitor | CVE-2024-7659No exploit | projectsend Password Reset Token functions.php generate_random_string random valuesprojectsend · projectsend · CWE-330 | Medium6.3 | — | 0.8% | Aug 12, 2024 |
24Monitor | CVE-2019-11533No exploit | Cross-site scripting (XSS) vulnerability in ProjectSend before r1070 allows remote attackers to inject arbitrary web script or HTML.projectsend · projectsend · CWE-79 | Medium6.1 | — | 1.2% | Apr 26, 2019 |
24Monitor | CVE-2017-9783No exploit | Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remoteprojectsend · projectsend · CWE-79 | Medium6.1 | — | 1.1% | Mar 6, 2018 |
24Monitor | CVE-2017-9786No exploit | Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remoteprojectsend · projectsend · CWE-79 | Medium6.1 | — | 1.0% | Mar 6, 2018 |
24Monitor | CVE-2018-7202No exploit | An issue was discovered in ProjectSend before r1053.projectsend · projectsend · CWE-79 | Medium6.1 | — | 0.8% | May 22, 2019 |
24Monitor | CVE-2023-53905No exploit | ProjectSend r1605 CSV Injection via User Account Export Functionalityprojectsend · projectsend · CWE-1236 | Medium6.2 | — | 0.5% | Dec 17, 2025 |
22Monitor | CVE-2017-20101No exploit | ProjectSend information disclosureprojectsend · projectsend · CWE-200 | Medium5.7 | — | 1.1% | Jun 27, 2022 |
- CVE-2024-1168097Now
ProjectSend Unauthenticated Configuration Modification
CriticalCVSS 9.8KEVWeaponizedEPSS 92%projectsend · projectsendNov 26, 2024
- CVE-2014-956743Plan
Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows remote attackers to exe
HighCVSS 7.5WeaponizedEPSS 43%projectsend · projectsendJan 7, 2015
- CVE-2021-4088740Plan
Projectsend version r1295 is affected by a directory traversal vulnerability.
CriticalCVSS 9.8No exploitEPSS 2%projectsend · projectsendOct 11, 2021
- CVE-2016-1073340Plan
ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string.
CriticalCVSS 9.8No exploitEPSS 2%projectsend · projectsendOct 29, 2018
- CVE-2016-1073240Plan
ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or proc
CriticalCVSS 9.8No exploitEPSS 2%projectsend · projectsendOct 29, 2018
- CVE-2017-974139Monitor
install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to rep
CriticalCVSS 9.8No exploitEPSS 2%projectsend · projectsendJun 18, 2017
- CVE-2016-1073439Monitor
ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.
CriticalCVSS 9.8No exploitEPSS 2%projectsend · projectsendOct 29, 2018
- CVE-2016-1073139Monitor
ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the requ
CriticalCVSS 9.8No exploitEPSS 1%projectsend · projectsendOct 29, 2018
- CVE-2019-1137836Monitor
An issue was discovered in ProjectSend r1053.
HighCVSS 8.8No exploitEPSS 4%projectsend · projectsendApr 20, 2019
- CVE-2018-720135Monitor
CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel.
HighCVSS 8.8No exploitEPSS 1%projectsend · projectsendMay 22, 2019
- CVE-2023-5398034Monitor
ProjectSend r1605 Remote Code Execution via File Extension Manipulation
HighCVSS 8.7No exploitEPSS 1%projectsend · projectsendDec 22, 2025
- CVE-2021-4088432Monitor
Projectsend version r1295 is affected by sensitive information disclosure.
HighCVSS 8.1No exploitEPSS 1%projectsend · projectsendOct 11, 2021
- CVE-2020-2887431Monitor
reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic.
HighCVSS 7.5Proof of conceptEPSS 2%projectsend · projectsendJan 26, 2021
- CVE-2019-1149230Monitor
ProjectSend before r1070 writes user passwords to the server logs.
HighCVSS 7.5No exploitEPSS 1%projectsend · projectsendApr 26, 2019
- CVE-2023-5393028Monitor
ProjectSend r1605 Insecure Direct Object Reference File Download Vulnerability
HighCVSS 7.1No exploitEPSS 0%projectsend · projectsendDec 17, 2025
- CVE-2015-256427Monitor
SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to execute arbitrary SQ
MediumCVSS 6.5Proof of conceptEPSS 3%projectsend · projectsendMar 20, 2015
- CVE-2024-765827Monitor
projectsend process.php get_preview resource injection
MediumCVSS 6.9No exploitEPSS 1%projectsend · projectsendAug 12, 2024
- CVE-2021-4088626Monitor
Projectsend version r1295 is affected by a directory traversal vulnerability.
MediumCVSS 6.5No exploitEPSS 1%projectsend · projectsendOct 11, 2021
- CVE-2024-765925Monitor
projectsend Password Reset Token functions.php generate_random_string random values
MediumCVSS 6.3No exploitEPSS 1%projectsend · projectsendAug 12, 2024
- CVE-2019-1153324Monitor
Cross-site scripting (XSS) vulnerability in ProjectSend before r1070 allows remote attackers to inject arbitrary web script or HTML.
MediumCVSS 6.1No exploitEPSS 1%projectsend · projectsendApr 26, 2019
- CVE-2017-978324Monitor
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote
MediumCVSS 6.1No exploitEPSS 1%projectsend · projectsendMar 6, 2018
- CVE-2017-978624Monitor
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote
MediumCVSS 6.1No exploitEPSS 1%projectsend · projectsendMar 6, 2018
- CVE-2018-720224Monitor
An issue was discovered in ProjectSend before r1053.
MediumCVSS 6.1No exploitEPSS 1%projectsend · projectsendMay 22, 2019
- CVE-2023-5390524Monitor
ProjectSend r1605 CSV Injection via User Account Export Functionality
MediumCVSS 6.2No exploitEPSS 1%projectsend · projectsendDec 17, 2025
- CVE-2017-2010122Monitor
ProjectSend information disclosure
MediumCVSS 5.7No exploitEPSS 1%projectsend · projectsendJun 27, 2022