Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Projeqtor

First CVE: Nov 14, 2013Active for: 13 yearsTotal CVEs: 14
43.2
VTI Score
High

Projeqtor is an open-source project management and planning application whose vulnerability footprint concentrates in a single, widely deployed web-facing product. Its disclosures skew toward serious outcomes and frequently acquire public exploit code, driven by a durable pattern of input-handling and code-generation weaknesses including cross-site scripting, SQL injection, code injection, and unrestricted file uploads that are characteristic of web applications with broad user access. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Projeqtor over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 14, 2013
12 years ago
Most Recent CVE
Apr 27, 2026
88 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-18924HIGH
The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" because rejected files remain on the serve
Nov 4, 20188.842NOYES
CVE-2026-41462CRITICAL
ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is directly concatenated into a SQL
Apr 27, 20269.837NONO
CVE-2026-41463HIGH
ProjeQtor versions 7.0 through 12.4.3 contain a ZipSlip path traversal vulnerability in the plugin upload functionality that allows authenticated attackers with upload permissions
Apr 27, 20268.833NONO
CVE-2021-42940CRITICAL
A Cross Site Scripting (XSS) vulnerability exists in Projeqtor 9.3.1 via /projeqtor/tool/saveAttachment.php, which allows an attacker to upload a SVG file containing malicious Java
Feb 11, 20229.930NONO
CVE-2013-6164HIGH
SQL injection vulnerability in view/objectDetail.php in Project'Or RIA 3.4.0 allows remote attackers to execute arbitrary SQL commands via the objectId parameter.
Nov 14, 20137.529NOYES
CVE-2026-41465MEDIUM
ProjeQtor versions 7.0 through 12.4.3 contain a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against direct
Apr 27, 20266.526NONO
CVE-2026-41464MEDIUM
ProjeQtor versions 7.0 through 12.4.3 contain a missing authorization vulnerability in the objectDetail.php endpoint that allows authenticated users with guest-level privileges to
Apr 27, 20266.526NONO
CVE-2024-29387HIGH
projeqtor up to 11.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /view/print.php.
Apr 4, 20248.824NONO
CVE-2026-41467MEDIUM
ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the file upload functionality where the checkValidFileName() function fails to restrict
Apr 27, 20265.423NONO
CVE-2026-41466MEDIUM
ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the checkValidHtmlText() function within Security.php that fails to properly sanitize u
Apr 27, 20265.423NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
50%
36%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (85.7%)
Unknown2 (14.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (85.7%)
High0 (0.0%)
Unknown2 (14.3%)
User Interaction
None9 (64.3%)
Unknown2 (14.3%)
Required3 (21.4%)
Privileges Required
Low10 (71.4%)
High0 (0.0%)
None2 (14.3%)
Unknown2 (14.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
14.3% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Projeqtor.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Projeqtor — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Projeqtor's Products

View all 2 CNAs →

Top CWEs