Bdtask is a provider of enterprise and healthcare management software, with a focused portfolio spanning inventory systems, hospital administration platforms, and clinical consultation applications. The vendor's vulnerability footprint concentrates on a narrow set of web-facing products and recurs through application-layer weakness classes including cross-site scripting, cross-site request forgery, improper access control, unrestricted file uploads, and authorization bypass, which are characteristic of web application development practices. These weakness classes collectively reflect common gaps in input validation, session management, and access enforcement that affect healthcare and administrative software where user-facing forms and file handling are core functionality. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bdtask over time
Signals from CVEs in this vendor scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28993CRITICAL Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request. | May 20, 2022 | 9.8 | 30 | NO | NO |
CVE-2025-13238HIGH A weakness has been identified in Bdtask Flight Booking Software 4. Affected by this vulnerability is an unknown functionality of the file /agent/profile/edit of the component Edit | Nov 16, 2025 | 8.8 | 28 | NO | NO |
CVE-2026-1597HIGH A vulnerability has been found in Bdtask SalesERP up to 20260116. This issue affects some unknown processing of the component Administrative Endpoint. Such manipulation of the argu | Jan 29, 2026 | 8.8 | 27 | NO | NO |
CVE-2025-13177HIGH A vulnerability was detected in Bdtask/CodeCanyon SalesERP up to 20250728. This affects an unknown part. The manipulation results in cross-site request forgery. The attack can be e | Nov 14, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-12288HIGH A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4. Affected is an unknown function of the file /user/edit_user/ of the component User Profile Handler. Per | Oct 27, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-12223HIGH A vulnerability was detected in Bdtask Flight Booking Software up to 3.1. This affects an unknown part of the file /b2c/package-information of the component Package Information Mod | Oct 27, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-12222HIGH A security vulnerability has been detected in Bdtask Flight Booking Software up to 3.1. Affected by this issue is some unknown functionality of the file /admin/transaction/deposit | Oct 27, 2025 | 8.8 | 27 | NO | NO |
CVE-2019-25505HIGH Tradebox 5.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the symbol parameter. Attacker | Mar 4, 2026 | 7.1 | 24 | NO | NO |
CVE-2025-13239HIGH A security vulnerability has been detected in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution 5. Affected by this issue is some unknown functionality of the f | Nov 16, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-13185HIGH A security flaw has been discovered in Bdtask/CodeCanyon News365 up to 7.0.3. This affects an unknown function of the file /admin/dashboard/profile. The manipulation of the argumen | Nov 14, 2025 | 7.2 | 24 | NO | NO |
Signals from CVEs in this vendor scope (35 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bdtask.
Media articles that mention a CVE ID that affects a product developed by Bdtask — matched by CVE ID, not by vendor name.