Pleasanter is a modestly represented web-based project and task-management platform whose vulnerability profile concentrates in a single product with an outsized prominence in tracked disclosures. Its recurring weakness classes—cross-site scripting, improper access control, path traversal, and open redirect—reflect the input-handling and authorization demands of a web application exposed to user-supplied content and navigation flows. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pleasanter over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-21584MEDIUM Pleasanter 1.3.49.0 and earlier contains a cross-site scripting vulnerability. If an attacker tricks the user to access the product with a specially crafted URL and perform a speci | Mar 12, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-46688MEDIUM Open redirect vulnerability in Pleasanter 1.3.47.0 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL. | Dec 6, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-30758MEDIUM Cross-site scripting vulnerability in Pleasanter 1.3.38.1 and earlier allows a remote authenticated attacker to inject an arbitrary script. | Jun 1, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-32608MEDIUM Directory traversal vulnerability in Pleasanter (Community Edition and Enterprise Edition) 1.3.39.2 and earlier versions allows a remote authenticated attacker to alter an arbitrar | Jun 30, 2023 | 6.5 | 17 | NO | NO |
CVE-2023-34439MEDIUM Pleasanter 1.3.47.0 and earlier contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the user's web brow | Dec 6, 2023 | 5.4 | 16 | NO | NO |
CVE-2023-45210MEDIUM Pleasanter 1.3.47.0 and earlier contains an improper access control vulnerability, which may allow a remote authenticated attacker to view the temporary files uploaded by other use | Dec 6, 2023 | 4.3 | 15 | NO | NO |
CVE-2023-32607MEDIUM Stored cross-site scripting vulnerability in Pleasanter (Community Edition and Enterprise Edition) 1.3.39.2 and earlier versions allows a remote authenticated attacker to inject a | Jun 30, 2023 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pleasanter.
Media articles that mention a CVE ID that affects a product developed by Pleasanter — matched by CVE ID, not by vendor name.