Dylanjkotze maintains the Zephyr Project Manager application, a modestly represented vulnerability footprint centered on web-application security issues. The recurring signal involves authorization bypass through user-controlled keys and cross-site scripting vulnerabilities in web-page generation, reflecting common input-handling and access-control weaknesses in this product category. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dylanjkotze over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7624HIGH The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is due to the plugin not properly | Aug 15, 2024 | 8.1 | 25 | NO | NO |
CVE-2022-1822MEDIUM The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘project’ parameter in versions up to, and including, 3.2.40 due to insuffic | Jun 13, 2022 | 6.1 | 22 | NO | NO |
CVE-2025-12496MEDIUM The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.203 via the `file` parameter. This makes it possible | Dec 17, 2025 | 4.9 | 19 | NO | NO |
CVE-2024-43916HIGH Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.102. | Aug 26, 2024 | 7.1 | 19 | NO | NO |
CVE-2025-10490MEDIUM The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.3.202 due to insufficient in | Sep 26, 2025 | 4.4 | 18 | NO | NO |
CVE-2024-7356MEDIUM The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘filename’ parameter in all versions up to, and including, 3.3.100 due to insuf | Aug 3, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-6536MEDIUM The Zephyr Project Manager WordPress plugin before 3.3.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors and admins to pe | Jul 30, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dylanjkotze.
Media articles that mention a CVE ID that affects a product developed by Dylanjkotze — matched by CVE ID, not by vendor name.