projectsend has 2 CVEs on record between 2021 and 2024. The median CVSS is 8.7 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 50% vs 1% corpus
- Median CVSS
- 8.7
- Publish → KEV
- —(1)
- Last 90 days
- 0 prev 0
2
Total CVEs
1
Critical
1
CISA KEV
1
Exploited
Worst active — by depth score
projectsend vulnerabilities
CVEs affecting projectsend, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2024-11680Critical· 9.8CISA KEVPoCProjectSend versions prior to r1720 are affected by an improper authentication vulnerability
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of …
▾ Hadalprojectsend · projectsendEPSS 92%via NVD
CVE-2020-28874High· 7.5PoCreset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic
reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).
▾ Midnightprojectsend · projectsendEPSS 2.4%via NVD