Flyspray is a lightweight, open-source issue-tracking and project-management application with a modestly represented vulnerability footprint concentrated in a single product line. Its disclosures recur through web-application input-handling and session-management weakness classes, including cross-site scripting, cross-site request forgery, and sensitive-information exposure, which reflect the attack surface inherent to publicly exposed tracking and collaboration tools; the vendor's vulnerabilities frequently acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flyspray over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1058MEDIUM Cross-site request forgery (CSRF) vulnerability in Flyspray 0.9.9.6 allows remote attackers to hijack the authentication of admins for requests that add admin accounts via an admin | Feb 14, 2012 | 6.0 | 29 | NO | YES |
CVE-2006-0714MEDIUM Directory traversal vulnerability in the installation file (sql/install-0.9.7.php) in Flyspray 0.9.7 allows remote attackers to include arbitrary files via a .. (dot dot) sequence | Feb 15, 2006 | 5.0 | 25 | NO | YES |
CVE-2005-3334MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Flyspray 0.9.7 through 0.9.8 (devel) allows remote attackers to inject arbitrary web script or HTML via the (1) PHPSESSID, | Oct 27, 2005 | 4.3 | 22 | NO | YES |
CVE-2007-1789MEDIUM Flyspray 0.9.9 allows remote attackers to obtain sensitive information (private project summaries) via direct requests. | Mar 31, 2007 | 6.8 | 20 | NO | NO |
CVE-2017-15213MEDIUM Stored XSS vulnerability in Flyspray before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges, via the real_name or email_address field to | Oct 11, 2017 | 5.4 | 19 | NO | NO |
CVE-2017-15214MEDIUM Stored XSS vulnerability in Flyspray 1.0-rc4 before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges and also to execute JavaScript agains | Oct 11, 2017 | 5.4 | 18 | NO | NO |
CVE-2007-1788MEDIUM Flyspray 0.9.9, when output_buffering is disabled or "set to a low value," allows remote attackers to bypass authentication via a crafted post request. | Mar 31, 2007 | 6.8 | 18 | NO | NO |
CVE-2008-1166MEDIUM Flyspray 0.9.9.4 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames. | Mar 5, 2008 | 5.0 | 17 | NO | NO |
CVE-2008-1165MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Flyspray 0.9.9 through 0.9.9.4 allow remote attackers to inject arbitrary web script or HTML via (1) a forced SQL error messa | Mar 5, 2008 | 4.3 | 14 | NO | NO |
CVE-2007-6461MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flyspray 0.9.9 through 0.9.9.3 allow remote attackers to inject arbitrary web script or HTML via (1) the query s | Dec 20, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flyspray.
Media articles that mention a CVE ID that affects a product developed by Flyspray — matched by CVE ID, not by vendor name.