Webtareas Project maintains a focused web application that, despite a narrow product portfolio, has accumulated a meaningful vulnerability history concentrated in a single core product. Vulnerabilities affecting this vendor skew toward critical severity and frequently acquire public exploit code, reflecting the application's web-facing attack surface and the inherent exploitability of input-handling and file-management flaws. The exposure recurs consistently through application-layer weakness classes including cross-site scripting, SQL injection, unrestricted file upload, path traversal, and cross-site request forgery, which are characteristic of web applications lacking robust input validation and access controls. Defenders should treat this vendor's advisories as requiring prompt patching and should audit deployed instances for these recurring weakness patterns; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webtareas Project over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-44291CRITICAL webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php. | Dec 2, 2022 | 9.8 | 47 | NO | YES |
CVE-2022-44290CRITICAL webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php. | Dec 2, 2022 | 9.8 | 47 | NO | YES |
CVE-2021-43481CRITICAL An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php. | Apr 20, 2022 | 9.8 | 46 | NO | YES |
CVE-2022-44957MEDIUM webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /clients/listclients.php. This vulnerability allows attackers to execute arbit | Dec 2, 2022 | 5.4 | 32 | NO | YES |
CVE-2023-53971HIGH WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functionality. Attackers can upload a | Dec 22, 2025 | 8.8 | 29 | NO | NO |
CVE-2021-41919HIGH webTareas version 2.4 and earlier allows an authenticated user to arbitrarily upload potentially dangerous files without restrictions. This is working by adding or replacing a pers | Oct 8, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-41916HIGH A Cross-Site Request Forgery (CSRF) vulnerability in webTareas version 2.4 and earlier allows a remote attacker to create a new administrative profile and add a new user to the new | Oct 8, 2021 | 8.8 | 27 | NO | NO |
CVE-2023-53972HIGH WebTareas 2.4 contains a SQL injection vulnerability in the webTareasSID cookie parameter that allows unauthenticated attackers to manipulate database queries. Attackers can exploi | Dec 22, 2025 | 7.5 | 26 | NO | NO |
CVE-2021-41920HIGH webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor | Oct 8, 2021 | 7.5 | 24 | NO | NO |
CVE-2020-25733HIGH webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types. | Sep 18, 2020 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webtareas Project.
Media articles that mention a CVE ID that affects a product developed by Webtareas Project — matched by CVE ID, not by vendor name.