Projeqtor is an open-source project management and planning application whose vulnerability footprint concentrates in a single, widely deployed web-facing product. Its disclosures skew toward serious outcomes and frequently acquire public exploit code, driven by a durable pattern of input-handling and code-generation weaknesses including cross-site scripting, SQL injection, code injection, and unrestricted file uploads that are characteristic of web applications with broad user access. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Projeqtor over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18924HIGH The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" because rejected files remain on the serve | Nov 4, 2018 | 8.8 | 42 | NO | YES |
CVE-2026-41462CRITICAL ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is directly concatenated into a SQL | Apr 27, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-41463HIGH ProjeQtor versions 7.0 through 12.4.3 contain a ZipSlip path traversal vulnerability in the plugin upload functionality that allows authenticated attackers with upload permissions | Apr 27, 2026 | 8.8 | 33 | NO | NO |
CVE-2021-42940CRITICAL A Cross Site Scripting (XSS) vulnerability exists in Projeqtor 9.3.1 via /projeqtor/tool/saveAttachment.php, which allows an attacker to upload a SVG file containing malicious Java | Feb 11, 2022 | 9.9 | 30 | NO | NO |
CVE-2013-6164HIGH SQL injection vulnerability in view/objectDetail.php in Project'Or RIA 3.4.0 allows remote attackers to execute arbitrary SQL commands via the objectId parameter. | Nov 14, 2013 | 7.5 | 29 | NO | YES |
CVE-2026-41465MEDIUM ProjeQtor versions 7.0 through 12.4.3 contain a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against direct | Apr 27, 2026 | 6.5 | 26 | NO | NO |
CVE-2026-41464MEDIUM ProjeQtor versions 7.0 through 12.4.3 contain a missing authorization vulnerability in the objectDetail.php endpoint that allows authenticated users with guest-level privileges to | Apr 27, 2026 | 6.5 | 26 | NO | NO |
CVE-2024-29387HIGH projeqtor up to 11.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /view/print.php. | Apr 4, 2024 | 8.8 | 24 | NO | NO |
CVE-2026-41467MEDIUM ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the file upload functionality where the checkValidFileName() function fails to restrict | Apr 27, 2026 | 5.4 | 23 | NO | NO |
CVE-2026-41466MEDIUM ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the checkValidHtmlText() function within Security.php that fails to properly sanitize u | Apr 27, 2026 | 5.4 | 23 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Projeqtor.
Media articles that mention a CVE ID that affects a product developed by Projeqtor — matched by CVE ID, not by vendor name.