Taskcafe Project maintains a task-management and collaboration platform with a narrow vulnerability footprint, where the durable signal centers on web application security issues including improper access control and cross-site scripting. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Taskcafe Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26770CRITICAL TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can change the password of that user. | Oct 4, 2024 | 9.8 | 28 | NO | NO |
CVE-2020-25400HIGH Cross domain policies in Taskcafe Project Management tool before version 0.1.0 and 0.1.1 allows remote attackers to access sensitive data such as access token. | Nov 17, 2020 | 7.5 | 23 | NO | NO |
CVE-2023-26771MEDIUM Taskcafe 0.3.2 is vulnerable to Cross Site Scripting (XSS). There is a lack of validation in the filetype when uploading a SVG profile picture with a XSS payload on it. An authenti | Oct 4, 2024 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Taskcafe Project.
Media articles that mention a CVE ID that affects a product developed by Taskcafe Project — matched by CVE ID, not by vendor name.