Unmark is a task and project management application whose vulnerability surface centers on web-layer input handling and code-generation flaws, with recurring exposures in cross-site scripting, code injection, and server-side request forgery. Treat this as a focused product profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unmark over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-10329CRITICAL A vulnerability was detected in cdevroe unmark up to 1.9.3. This affects an unknown part of the file /application/controllers/Marks.php. The manipulation of the argument url result | Sep 12, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-10330MEDIUM A flaw has been found in cdevroe unmark up to 1.9.3. This vulnerability affects unknown code of the file application/views/layouts/topbar/searchform.php. This manipulation of the a | Sep 12, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-10331MEDIUM A vulnerability has been found in cdevroe unmark up to 1.9.3. This issue affects some unknown processing of the file /application/controllers/Marks.php. Such manipulation of the ar | Sep 13, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-10332MEDIUM A vulnerability was found in cdevroe unmark up to 1.9.3. Impacted is an unknown function of the file application/views/marks/info.php. Performing manipulation of the argument Title | Sep 13, 2025 | 5.4 | 18 | NO | NO |
CVE-2024-41349MEDIUM unmark 1.9.2 is vulnerable to Cross Site Scripting (XSS) via application/views/marks/add_by_url.php. | Aug 29, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unmark.
Media articles that mention a CVE ID that affects a product developed by Unmark — matched by CVE ID, not by vendor name.