Projectpier is a web-based project management application with a narrow product scope but meaningful presence in self-hosted collaboration environments. Vulnerabilities affecting the vendor skew toward critical severity and frequently acquire public exploit code, with recurring weaknesses concentrated in input validation and handling across its application layer—including cross-site scripting, SQL injection, CSRF, file-upload restrictions, and sensitive-information exposure. Defenders deploying this software should prioritize patching and restrict network access to trusted users; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Projectpier over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-10036CRITICAL Project Pier 0.8.8 and earlier contains an unauthenticated arbitrary file upload vulnerability in tools/upload_file.php. The upload handler fails to validate the file type or enfor | Aug 8, 2025 | 9.3 | 46 | NO | YES |
CVE-2018-10759CRITICAL PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and earlier allows remote attackers to execute arbitrary commands or SQL statements via the | May 16, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-10760HIGH Unrestricted file upload vulnerability in the Files plugin in ProjectPier 0.88 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading a file with | May 16, 2018 | 8.8 | 22 | NO | NO |
CVE-2008-5584MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in ProjectPier 0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) a message, (2) a milestone, | Dec 15, 2008 | 4.3 | 22 | NO | YES |
CVE-2015-2796MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Project-Pier ProjectPier-Core allow remote attackers to inject arbitrary web script or HTML via the search_for parameter to ( | Feb 2, 2018 | 6.1 | 19 | NO | NO |
CVE-2008-5583MEDIUM Cross-site request forgery (CSRF) vulnerability in index.php in ProjectPier 0.8 and earlier allows remote attackers to perform actions as an administrator via the query string, as | Dec 15, 2008 | 6.8 | 18 | NO | NO |
CVE-2011-3797MEDIUM ProjectPier 0.8.0.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonst | Sep 24, 2011 | 5.0 | 17 | NO | NO |
CVE-2013-3636MEDIUM ProjectPier 0.8.8 has a Remote Information Disclosure Weakness because of the lack of the HttpOnly cookie flag | Feb 7, 2020 | 5.4 | 16 | NO | NO |
CVE-2013-3637MEDIUM ProjectPier 0.8.8 does not use the Secure flag for cookies | Feb 7, 2020 | 5.4 | 15 | NO | NO |
CVE-2013-3635MEDIUM ProjectPier 0.8.8 has stored XSS | Feb 7, 2020 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Projectpier.
Media articles that mention a CVE ID that affects a product developed by Projectpier — matched by CVE ID, not by vendor name.