Boldworkplanner is a project and work-management application where the durable vulnerability signal centers on authorization-bypass conditions tied to user-controlled cryptographic or session keys. The product's exposure reflects the access-control demands of collaborative planning software where session integrity and privilege boundaries must be enforced correctly. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Boldworkplanner over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-41098HIGH Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a misuse of the general enquiry web service. | Sep 30, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-41099MEDIUM Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allo | Sep 30, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-41097MEDIUM Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allo | Sep 30, 2025 | 4.3 | 17 | NO | NO |
CVE-2025-41096MEDIUM Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allo | Sep 30, 2025 | 4.3 | 17 | NO | NO |
CVE-2025-41095MEDIUM Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allo | Sep 30, 2025 | 4.3 | 17 | NO | NO |
CVE-2025-41094MEDIUM Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allo | Sep 30, 2025 | 4.3 | 17 | NO | NO |
CVE-2025-41093MEDIUM Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allo | Sep 30, 2025 | 4.3 | 17 | NO | NO |
CVE-2025-41092MEDIUM Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allo | Sep 30, 2025 | 4.3 | 17 | NO | NO |
CVE-2025-41091MEDIUM Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allo | Sep 30, 2025 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Boldworkplanner.
Media articles that mention a CVE ID that affects a product developed by Boldworkplanner — matched by CVE ID, not by vendor name.