Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-5292

22
FAUCET Score

CVE-2020-5292 describes a high-impact SQL Injection vulnerability in Leantime versions prior to 2.0.15 and 2.1-beta3. This flaw allows authenticated attackers to execute arbitrary SQL queries by manipulating the "searchUsers" parameter in a POST request to "/tickets/showKanban". Successful exploitation can lead to complete compromise of confidentiality, integrity, and availability, including data exfiltration of password hashes, data modification, or database destruction. The vulnerability has a CVSS v3.1 score of 8.8 (High), indicating it is network-exploitable with low attack complexity and requires low privileges, but no user interaction. Its EPSS score is very low, suggesting a minimal probability of exploitation in the wild. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE. It is not listed in CISA's Known Exploited Vulnerabilities Catalog.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.0.15CPE matchmatch criteria
cpe:2.3:a:leantime:leantime:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.7HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.3
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.41%
Probability of exploitation in next 30 days
EPSS Percentile
69.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0140 is in the 67th percentile among its peer group of 17,823 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / Leantime/leantime/commit/af0807f0b2c4c3c914b93f1c5d940e6b875f231f
PatchThird Party Advisory
github.com / Leantime/leantime/pull/181
PatchThird Party Advisory
github.com / Leantime/leantime/security/advisories/GHSA-ww6x-rhvp-55hp
Third Party Advisory