Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Leantime

First CVE: Mar 31, 2020Active for: 6 yearsTotal CVEs: 11
38.1
VTI Score
Medium

Leantime is a project-management and work-tracking application whose vulnerability footprint concentrates in a single product and centers on application-layer input-handling weaknesses such as cross-site scripting, SQL injection, code injection, and cross-site request forgery. The vendor's disclosed issues recur through patterns typical of web applications lacking robust input validation and output encoding, and public exploit code has a tendency to become available for vulnerabilities in this class. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
2.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 47% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Leantime over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 31, 2020
6 years ago
Most Recent CVE
Jul 6, 2026
18 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-59713HIGH
Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters. Attackers can craft malicious
Jul 6, 20268.133NONO
CVE-2026-59712HIGH
Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to retrieve full user credential rows including password hashes
Jul 6, 20268.131NONO
CVE-2023-45826MEDIUM
Leantime is an open source project management system. A 'userId' variable in `app/domain/files/repositories/class.files.php` is not parameterized. An authenticated attacker can sen
Oct 19, 20236.528NOYES
CVE-2024-27474HIGH
Leantime 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF). This vulnerability allows malicious actors to perform unauthorized actions on behalf of authenticated users, spec
Apr 10, 20248.825NONO
CVE-2020-5292HIGH
Leantime before versions 2.0.15 and 2.1-beta3 has a SQL Injection vulnerability. The impact is high. Malicious users/attackers can execute arbitrary SQL queries negatively affectin
Mar 31, 20208.822NONO
CVE-2024-27705HIGH
Cross Site Scripting vulnerability in Leantime v3.0.6 allows attackers to execute arbitrary code via upload of crafted PDF file to the files/browse endpoint.
Apr 3, 20247.621NONO
CVE-2024-27477MEDIUM
In Leantime 3.0.6, a Cross-Site Scripting vulnerability exists within the ticket creation and modification functionality, allowing attackers to inject malicious JavaScript code int
Apr 10, 20246.119NONO
CVE-2023-33961MEDIUM
Leantime is a lean open source project management system. Starting in version 2.3.21, an authenticated user with commenting privileges can inject malicious Javascript into a commen
May 30, 20235.419NONO
CVE-2025-28254MEDIUM
Cross Site Scripting vulnerability in Leantime v3.2.1 and before allows an authenticated attacker to execute arbitrary code and obtain sensitive information via the first name fiel
Mar 28, 20255.418NONO
CVE-2024-27476MEDIUM
Leantime 3.0.6 is vulnerable to HTML Injection via /dashboard/show#/tickets/newTicket.
Apr 10, 20244.717NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
55%
45%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network10 (90.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (9.1%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (36.4%)
Unknown0 (0.0%)
Required7 (63.6%)
Privileges Required
Low6 (54.5%)
High0 (0.0%)
None5 (45.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
9.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Leantime.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Leantime — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Leantime's Products

View all 3 CNAs →

Top CWEs