Записи ProjectSend
29 опубликованных записей вендора projectsend.
Профиль для исследователя
- Попали в KEV
- 1 · 3,4 %
- С эксплойтом
- 2 · 6,9 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- 7 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-287 Improper Authentication2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File2
- CWE-330 Use of Insufficiently Random Values1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
29 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
97Срочно | CVE-2024-11680Готовый эксплойт | ProjectSend Unauthenticated Configuration Modificationprojectsend · projectsend · CWE-306 | Критическая9,8 | KEV | 91,7 % | 26 нояб. 2024 г. |
43В плане | CVE-2014-9567Готовый эксплойт | Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows remote attackers to exeprojectsend · projectsend · CWE-94 | Высокая7,5 | — | 43,3 % | 7 янв. 2015 г. |
40В плане | CVE-2021-40887Эксплойта нет | Projectsend version r1295 is affected by a directory traversal vulnerability.projectsend · projectsend · CWE-22 | Критическая9,8 | — | 2,4 % | 11 окт. 2021 г. |
40В плане | CVE-2016-10733Эксплойта нет | ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string.projectsend · projectsend · CWE-22 | Критическая9,8 | — | 2,1 % | 29 окт. 2018 г. |
40В плане | CVE-2016-10732Эксплойта нет | ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or procprojectsend · projectsend · CWE-287 | Критическая9,8 | — | 1,9 % | 29 окт. 2018 г. |
39Наблюдать | CVE-2017-9741Эксплойта нет | install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to repprojectsend · projectsend · CWE-20 | Критическая9,8 | — | 1,6 % | 18 июн. 2017 г. |
39Наблюдать | CVE-2016-10734Эксплойта нет | ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.projectsend · projectsend · CWE-285 | Критическая9,8 | — | 1,5 % | 29 окт. 2018 г. |
39Наблюдать | CVE-2016-10731Эксплойта нет | ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the requprojectsend · projectsend · CWE-89 | Критическая9,8 | — | 1,4 % | 29 окт. 2018 г. |
36Наблюдать | CVE-2019-11378Эксплойта нет | An issue was discovered in ProjectSend r1053.projectsend · projectsend · CWE-22 | Высокая8,8 | — | 3,6 % | 20 апр. 2019 г. |
35Наблюдать | CVE-2018-7201Эксплойта нет | CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel.projectsend · projectsend · CWE-1236 | Высокая8,8 | — | 1,3 % | 22 мая 2019 г. |
34Наблюдать | CVE-2023-53980Эксплойта нет | ProjectSend r1605 Remote Code Execution via File Extension Manipulationprojectsend · projectsend · CWE-434 | Высокая8,7 | — | 0,9 % | 22 дек. 2025 г. |
32Наблюдать | CVE-2021-40884Эксплойта нет | Projectsend version r1295 is affected by sensitive information disclosure.projectsend · projectsend · CWE-862 | Высокая8,1 | — | 1,0 % | 11 окт. 2021 г. |
31Наблюдать | CVE-2020-28874Proof of concept | reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic.projectsend · projectsend · CWE-287 | Высокая7,5 | — | 2,4 % | 26 янв. 2021 г. |
30Наблюдать | CVE-2019-11492Эксплойта нет | ProjectSend before r1070 writes user passwords to the server logs.projectsend · projectsend · CWE-532 | Высокая7,5 | — | 1,1 % | 26 апр. 2019 г. |
28Наблюдать | CVE-2023-53930Эксплойта нет | ProjectSend r1605 Insecure Direct Object Reference File Download Vulnerabilityprojectsend · projectsend · CWE-639 | Высокая7,1 | — | 0,4 % | 17 дек. 2025 г. |
27Наблюдать | CVE-2015-2564Proof of concept | SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to execute arbitrary SQprojectsend · projectsend · CWE-89 | Средняя6,5 | — | 3,1 % | 20 мар. 2015 г. |
27Наблюдать | CVE-2024-7658Эксплойта нет | projectsend process.php get_preview resource injectionprojectsend · projectsend · CWE-99 | Средняя6,9 | — | 0,8 % | 12 авг. 2024 г. |
26Наблюдать | CVE-2021-40886Эксплойта нет | Projectsend version r1295 is affected by a directory traversal vulnerability.projectsend · projectsend · CWE-22 | Средняя6,5 | — | 1,4 % | 11 окт. 2021 г. |
25Наблюдать | CVE-2024-7659Эксплойта нет | projectsend Password Reset Token functions.php generate_random_string random valuesprojectsend · projectsend · CWE-330 | Средняя6,3 | — | 0,8 % | 12 авг. 2024 г. |
24Наблюдать | CVE-2019-11533Эксплойта нет | Cross-site scripting (XSS) vulnerability in ProjectSend before r1070 allows remote attackers to inject arbitrary web script or HTML.projectsend · projectsend · CWE-79 | Средняя6,1 | — | 1,2 % | 26 апр. 2019 г. |
24Наблюдать | CVE-2017-9783Эксплойта нет | Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remoteprojectsend · projectsend · CWE-79 | Средняя6,1 | — | 1,1 % | 6 мар. 2018 г. |
24Наблюдать | CVE-2017-9786Эксплойта нет | Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remoteprojectsend · projectsend · CWE-79 | Средняя6,1 | — | 1,0 % | 6 мар. 2018 г. |
24Наблюдать | CVE-2018-7202Эксплойта нет | An issue was discovered in ProjectSend before r1053.projectsend · projectsend · CWE-79 | Средняя6,1 | — | 0,8 % | 22 мая 2019 г. |
24Наблюдать | CVE-2023-53905Эксплойта нет | ProjectSend r1605 CSV Injection via User Account Export Functionalityprojectsend · projectsend · CWE-1236 | Средняя6,2 | — | 0,5 % | 17 дек. 2025 г. |
22Наблюдать | CVE-2017-20101Эксплойта нет | ProjectSend information disclosureprojectsend · projectsend · CWE-200 | Средняя5,7 | — | 1,1 % | 27 июн. 2022 г. |
- CVE-2024-1168097Срочно
ProjectSend Unauthenticated Configuration Modification
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %projectsend · projectsend26 нояб. 2024 г.
- CVE-2014-956743В плане
Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows remote attackers to exe
ВысокаяCVSS 7,5Готовый эксплойтEPSS 43 %projectsend · projectsend7 янв. 2015 г.
- CVE-2021-4088740В плане
Projectsend version r1295 is affected by a directory traversal vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %projectsend · projectsend11 окт. 2021 г.
- CVE-2016-1073340В плане
ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %projectsend · projectsend29 окт. 2018 г.
- CVE-2016-1073240В плане
ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or proc
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %projectsend · projectsend29 окт. 2018 г.
- CVE-2017-974139Наблюдать
install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to rep
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %projectsend · projectsend18 июн. 2017 г.
- CVE-2016-1073439Наблюдать
ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %projectsend · projectsend29 окт. 2018 г.
- CVE-2016-1073139Наблюдать
ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the requ
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %projectsend · projectsend29 окт. 2018 г.
- CVE-2019-1137836Наблюдать
An issue was discovered in ProjectSend r1053.
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %projectsend · projectsend20 апр. 2019 г.
- CVE-2018-720135Наблюдать
CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %projectsend · projectsend22 мая 2019 г.
- CVE-2023-5398034Наблюдать
ProjectSend r1605 Remote Code Execution via File Extension Manipulation
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %projectsend · projectsend22 дек. 2025 г.
- CVE-2021-4088432Наблюдать
Projectsend version r1295 is affected by sensitive information disclosure.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %projectsend · projectsend11 окт. 2021 г.
- CVE-2020-2887431Наблюдать
reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic.
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %projectsend · projectsend26 янв. 2021 г.
- CVE-2019-1149230Наблюдать
ProjectSend before r1070 writes user passwords to the server logs.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %projectsend · projectsend26 апр. 2019 г.
- CVE-2023-5393028Наблюдать
ProjectSend r1605 Insecure Direct Object Reference File Download Vulnerability
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %projectsend · projectsend17 дек. 2025 г.
- CVE-2015-256427Наблюдать
SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to execute arbitrary SQ
СредняяCVSS 6,5Proof of conceptEPSS 3 %projectsend · projectsend20 мар. 2015 г.
- CVE-2024-765827Наблюдать
projectsend process.php get_preview resource injection
СредняяCVSS 6,9Эксплойта нетEPSS 1 %projectsend · projectsend12 авг. 2024 г.
- CVE-2021-4088626Наблюдать
Projectsend version r1295 is affected by a directory traversal vulnerability.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %projectsend · projectsend11 окт. 2021 г.
- CVE-2024-765925Наблюдать
projectsend Password Reset Token functions.php generate_random_string random values
СредняяCVSS 6,3Эксплойта нетEPSS 1 %projectsend · projectsend12 авг. 2024 г.
- CVE-2019-1153324Наблюдать
Cross-site scripting (XSS) vulnerability in ProjectSend before r1070 allows remote attackers to inject arbitrary web script or HTML.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %projectsend · projectsend26 апр. 2019 г.
- CVE-2017-978324Наблюдать
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote
СредняяCVSS 6,1Эксплойта нетEPSS 1 %projectsend · projectsend6 мар. 2018 г.
- CVE-2017-978624Наблюдать
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote
СредняяCVSS 6,1Эксплойта нетEPSS 1 %projectsend · projectsend6 мар. 2018 г.
- CVE-2018-720224Наблюдать
An issue was discovered in ProjectSend before r1053.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %projectsend · projectsend22 мая 2019 г.
- CVE-2023-5390524Наблюдать
ProjectSend r1605 CSV Injection via User Account Export Functionality
СредняяCVSS 6,2Эксплойта нетEPSS 1 %projectsend · projectsend17 дек. 2025 г.
- CVE-2017-2010122Наблюдать
ProjectSend information disclosure
СредняяCVSS 5,7Эксплойта нетEPSS 1 %projectsend · projectsend27 июн. 2022 г.