Rukovoditel is a project-management and workflow-automation platform with a modestly sized but notably active vulnerability footprint concentrated in its core self-hosted application. Vulnerabilities affecting the platform skew strongly toward critical-severity outcomes and frequently acquire public exploit tooling, driven by a recurrent cluster of web-application weaknesses including cross-site scripting, SQL injection, unsafe file uploads, cross-site request forgery, and code injection that are characteristic of server-side application development. The exposure pattern reflects both the input-handling demands of a form-heavy platform and the attack surface that arises when such tools are internet-accessible and often deployed in resource-constrained environments where patching cadence may lag. Defenders should prioritize patches for this vendor and restrict network access to administrative interfaces where feasible; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rukovoditel over time
Signals from CVEs in this vendor scope (52 CVEs).
52 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11819CRITICAL In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve command execution. | Apr 16, 2020 | 9.8 | 52 | NO | YES |
CVE-2018-20166HIGH A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a background image, and mishandles extension checking. It acc | Jan 2, 2019 | 8.8 | 41 | NO | YES |
CVE-2022-44945CRITICAL Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter. | Dec 2, 2022 | 9.8 | 34 | NO | NO |
CVE-2019-7400MEDIUM Rukovoditel before 2.4.1 allows XSS. | Feb 5, 2019 | 6.1 | 32 | NO | YES |
CVE-2022-44952MEDIUM Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in /index.php?module=configuration/application. This vulnerability allows attackers t | Dec 2, 2022 | 5.4 | 31 | NO | YES |
CVE-2022-44951MEDIUM Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Form tab function at /index.php?module=entities/forms&entities_id=24. | Dec 2, 2022 | 5.4 | 31 | NO | YES |
CVE-2022-44950MEDIUM Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. Th | Dec 2, 2022 | 5.4 | 31 | NO | YES |
CVE-2022-44949MEDIUM Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. Th | Dec 2, 2022 | 5.4 | 31 | NO | YES |
CVE-2022-44948MEDIUM Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group feature at/index.php?module=entities/entities_groups. This vuln | Dec 2, 2022 | 5.4 | 31 | NO | YES |
CVE-2022-44947MEDIUM Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Highlight Row feature at /index.php?module=entities/listing_types&entities_id= | Dec 2, 2022 | 5.4 | 31 | NO | YES |
Signals from CVEs in this vendor scope (52 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rukovoditel.
Media articles that mention a CVE ID that affects a product developed by Rukovoditel — matched by CVE ID, not by vendor name.