Fairsketch's vulnerability footprint centers on its Rise Ultimate Project Manager product, a web-based project-management application where the disclosure pattern reflects application-layer input-handling and access-control weaknesses. The recurring weakness classes—cross-site scripting, SQL injection, cross-site request forgery, resource injection, and missing authorization—are characteristic of web applications handling user input and session state, and the vendor's disclosures tend to acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fairsketch over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8945HIGH A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical. This vulnerability affects unknown code of the file /index.php/dashboar | Sep 17, 2024 | 8.8 | 43 | NO | YES |
CVE-2017-17999CRITICAL SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL commands via the search parameter to index.php/knowledge_base/get_ | Jan 23, 2018 | 9.8 | 42 | NO | YES |
CVE-2025-60378HIGH Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into invoices and messages. Injected content renders in emails, PDF | Oct 10, 2025 | 8.1 | 29 | NO | NO |
CVE-2025-63293MEDIUM FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user can append comments or upload attachments to tickets for whi | Nov 3, 2025 | 6.5 | 25 | NO | NO |
CVE-2019-18884HIGH index.php/team_members/add_team_member in RISE Ultimate Project Manager 2.3 has CSRF for adding authorized users. | Nov 13, 2019 | 8.8 | 25 | NO | NO |
CVE-2025-56807MEDIUM A cross-site scripting (XSS) vulnerability in FairSketch RISE Ultimate Project Manager & CRM 3.9.4 allows an administrator to store a JavaScript payload using the file explorer in | Sep 29, 2025 | 6.1 | 23 | NO | NO |
CVE-2025-41102MEDIUM HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a P | Nov 11, 2025 | 5.4 | 20 | NO | NO |
CVE-2017-11182MEDIUM In Rise Ultimate Project Manager v1.8, XSS vulnerabilities were found in the My Profile section. All input fields are vulnerable. | Jul 12, 2017 | 5.4 | 20 | NO | NO |
CVE-2025-41106MEDIUM HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a P | Nov 11, 2025 | 5.4 | 19 | NO | NO |
CVE-2025-41105MEDIUM HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a P | Nov 11, 2025 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fairsketch.
Media articles that mention a CVE ID that affects a product developed by Fairsketch — matched by CVE ID, not by vendor name.