Leantime is a project-management and work-tracking application whose vulnerability footprint concentrates in a single product and centers on application-layer input-handling weaknesses such as cross-site scripting, SQL injection, code injection, and cross-site request forgery. The vendor's disclosed issues recur through patterns typical of web applications lacking robust input validation and output encoding, and public exploit code has a tendency to become available for vulnerabilities in this class. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Leantime over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-59713HIGH Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters. Attackers can craft malicious | Jul 6, 2026 | 8.1 | 33 | NO | NO |
CVE-2026-59712HIGH Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to retrieve full user credential rows including password hashes | Jul 6, 2026 | 8.1 | 31 | NO | NO |
CVE-2023-45826MEDIUM Leantime is an open source project management system. A 'userId' variable in `app/domain/files/repositories/class.files.php` is not parameterized. An authenticated attacker can sen | Oct 19, 2023 | 6.5 | 28 | NO | YES |
CVE-2024-27474HIGH Leantime 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF). This vulnerability allows malicious actors to perform unauthorized actions on behalf of authenticated users, spec | Apr 10, 2024 | 8.8 | 25 | NO | NO |
CVE-2020-5292HIGH Leantime before versions 2.0.15 and 2.1-beta3 has a SQL Injection vulnerability. The impact is high. Malicious users/attackers can execute arbitrary SQL queries negatively affectin | Mar 31, 2020 | 8.8 | 22 | NO | NO |
CVE-2024-27705HIGH Cross Site Scripting vulnerability in Leantime v3.0.6 allows attackers to execute arbitrary code via upload of crafted PDF file to the files/browse endpoint. | Apr 3, 2024 | 7.6 | 21 | NO | NO |
CVE-2024-27477MEDIUM In Leantime 3.0.6, a Cross-Site Scripting vulnerability exists within the ticket creation and modification functionality, allowing attackers to inject malicious JavaScript code int | Apr 10, 2024 | 6.1 | 19 | NO | NO |
CVE-2023-33961MEDIUM Leantime is a lean open source project management system. Starting in version 2.3.21, an authenticated user with commenting privileges can inject malicious Javascript into a commen | May 30, 2023 | 5.4 | 19 | NO | NO |
CVE-2025-28254MEDIUM Cross Site Scripting vulnerability in Leantime v3.2.1 and before allows an authenticated attacker to execute arbitrary code and obtain sensitive information via the first name fiel | Mar 28, 2025 | 5.4 | 18 | NO | NO |
CVE-2024-27476MEDIUM Leantime 3.0.6 is vulnerable to HTML Injection via /dashboard/show#/tickets/newTicket. | Apr 10, 2024 | 4.7 | 17 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Leantime.
Media articles that mention a CVE ID that affects a product developed by Leantime — matched by CVE ID, not by vendor name.