VulnSea

leantime vulnerabilities

CVEs whose affected-version data names the leantime package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-94211Low· 2.4PoC
today

A vulnerability has been found in Hyve5 Leantime up to 3.9.8

A vulnerability has been found in Hyve5 Leantime up to 3.9.8. Affected by this issue is some unknown functionality of the file /app/Domain/Dashboard/Templates/show.blade.php of the component Project Dashboard. Such manipulation leads to …

TwilightHyve5 · Leantimevia NVD
CVE-2026-94210Low· 3.5PoC
today

A flaw has been found in Hyve5 Leantime up to 3.9.8

A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this vulnerability is the function getAllGrouped of the file app/Domain/Tickets/Services/Tickets.php of the component Kanban Board. This manipulation causes cross site scri…

TwilightHyve5 · Leantimevia NVD
CVE-2026-92772High· 7.1PoC
5d ago

Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation

Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary prope…

MidnightLeantime · leantimeEPSS 0.38%via NVD
CVE-2026-59713High· 8.1
2mo ago

Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters

Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters. Attackers can craft malicious callback URLs with attacker-controlled authorization code…

TwilightLeantime · LeantimeEPSS 0.23%via NVD
CVE-2026-59712High· 8.1
2mo ago

Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to retrieve full user credential rows including password hashes, TOTP secrets, and session tokens

Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to retrieve full user credential rows including password hashes, TOTP secrets, and session tokens. Attackers can exploit…

TwilightLeantime · LeantimeEPSS 0.45%via NVD
leantime vulnerabilities (CVEs) · VulnSea