Vulnerabilidades em Leantime
10 resultadosAnálise Vexday
Leantime apresenta 5 vulnerabilidades registradas, com 2 divulgadas nos últimos 90 dias, indicando atividade recente de descobertas. A fraqueza dominante é injeção SQL (CWE-89), historicamente a mais explorada em aplicações web, embora nenhuma esteja sob ataque ativo catalogado no momento. Não há CVEs críticas associadas ao fornecedor na base, reduzindo o risco imediato, mas a tendência de descobertas recentes recomenda monitoramento contínuo.
CVE-2023-45826MEDIUMAuthenticated SQL Injection in leantimeEPSS 1.9%CVE-2020-5292HIGHTime-based blind injection in LeantimeEPSS 1.4%CVE-2023-33961HIGHLeantime Stored Cross-site Scripting VulnerabilityEPSS 0.4%CVE-2026-54418HIGHLeantime: Missing Authorization on TwoFA JSON-RPC Methods Allows Cross-Account 2FA Secret Disclosure and BypassEPSS 0.3%CVE-2026-66415HIGHLeantime Server-Side Request Forgery and Local File Inclusion in Blueprints::import()EPSS 0.3%CVE-2026-59712HIGHLeantime - JSON-RPC API Broken Access Control via users.getUserEPSS 0.3%CVE-2026-66412HIGHLeantime all versions prior to and 3.6.2 Broken Access Control via tickets.getMilestone JSON-RPCEPSS 0.2%CVE-2026-66414MEDIUMLeantime Open Redirect in Login Controller via redirectUrl ParameterEPSS 0.2%CVE-2026-66416HIGHLeantime CSRF Protection Globally Disabled by Omission of Laravel VerifyCsrfToken MiddlewareEPSS 0.2%CVE-2026-59713HIGHLeantime - OIDC Login CSRF via Unconditional State Verification StubEPSS 0.2%