Dootask is a project-management and collaboration platform with a focused product footprint, where observed vulnerabilities center on web-application input handling and file-upload controls. The recurring weakness classes—cross-site scripting and unrestricted file uploads—reflect the need for strict input validation and upload policy enforcement in web-facing productivity applications. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dootask over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-55454HIGH An authenticated arbitrary file upload vulnerability in the component /msg/sendfiles of DooTask v1.0.51 allows attackers to execute arbitrary code via uploading a crafted file. | Aug 22, 2025 | 8.8 | 28 | NO | NO |
CVE-2026-29828MEDIUM DooTask v1.6.27 has a Cross-Site Scripting (XSS) vulnerability in the /manage/project/<id> page via the input field projectDesc. | Mar 20, 2026 | 6.1 | 21 | NO | NO |
DooTask v1.0.51 was dicovered to contain an authenticated arbitrary download vulnerability via the component /msg/sendtext. | Aug 22, 2025 | 3.5 | 17 | NO | NO |
CVE-2024-34906MEDIUM An arbitrary file upload vulnerability in dootask v0.30.13 allows attackers to execute arbitrary code via uploading a crafted PDF file. | May 15, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dootask.
Media articles that mention a CVE ID that affects a product developed by Dootask — matched by CVE ID, not by vendor name.