Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Qdpm

First CVE: Mar 17, 2017Active for: 9 yearsTotal CVEs: 18
55.4
VTI Score
TOP TARGET

Qdpm is a modestly represented project management application that sits among more prominent products in the vulnerability landscape, with its exposure centered in a single product line. Vulnerabilities affecting the application skew toward serious outcomes and frequently acquire public exploit code; the recurring weakness classes—cross-site scripting, unrestricted file uploads, sensitive information exposure, path traversal, and SQL injection—reflect the input-handling and access-control demands of web-facing applications. Defenders should prioritize patching for this application in networked environments and treat it as a web-tier risk; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
2.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Qdpm over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 17, 2017
9 years ago
Most Recent CVE
Apr 5, 2026
110 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-7246HIGH
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the profile photo functionality, by leveraging a pa
Jan 21, 20208.883NOYES
CVE-2015-3884HIGH
Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) scheduler pages in qdPM 8.3 allows remote a
Mar 17, 20178.841NOYES
CVE-2022-26180HIGH
qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.
Apr 8, 20228.840NOYES
CVE-2019-8390MEDIUM
qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.
May 14, 20196.137NOYES
CVE-2023-45855HIGH
qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.
Oct 14, 20237.533NOYES
CVE-2020-11811CRITICAL
In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted content-type value. After that, the attacker c
Apr 16, 20209.832NONO
CVE-2020-19515MEDIUM
qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php.
Sep 9, 20216.131NOYES
CVE-2023-45856CRITICAL
qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.
Oct 14, 20239.830NONO
CVE-2019-25669HIGH
qdPM 9.1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the search_by_extrafields[] parameter. Attackers
Apr 5, 20268.227NONO
CVE-2020-26165HIGH
qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php because unserialize is used.
Dec 31, 20208.827NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
44%
44%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (55.6%)
Unknown0 (0.0%)
Required8 (44.4%)
Privileges Required
Low5 (27.8%)
High0 (0.0%)
None13 (72.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
11.1% of CVEs· 98th percentile
Nuclei
3 CVEs
16.7% of CVEs· 97th percentile
ExploitDB
4 CVEs
22.2% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Qdpm.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Qdpm — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Qdpm's Products

View all 2 CNAs →

Top CWEs