Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Webtareas Project

First CVE: Jun 22, 2020Active for: 6 yearsTotal CVEs: 27
41.1
VTI Score
High

Webtareas Project maintains a focused web application that, despite a narrow product portfolio, has accumulated a meaningful vulnerability history concentrated in a single core product. Vulnerabilities affecting this vendor skew toward critical severity and frequently acquire public exploit code, reflecting the application's web-facing attack surface and the inherent exploitability of input-handling and file-management flaws. The exposure recurs consistently through application-layer weakness classes including cross-site scripting, SQL injection, unrestricted file upload, path traversal, and cross-site request forgery, which are characteristic of web applications lacking robust input validation and access controls. Defenders should treat this vendor's advisories as requiring prompt patching and should audit deployed instances for these recurring weakness patterns; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
More Total CVEs than 97% of tracked vendors
6.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Webtareas Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 22, 2020
6 years ago
Most Recent CVE
Dec 22, 2025
215 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-44291CRITICAL
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
Dec 2, 20229.847NOYES
CVE-2022-44290CRITICAL
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.
Dec 2, 20229.847NOYES
CVE-2021-43481CRITICAL
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.
Apr 20, 20229.846NOYES
CVE-2022-44957MEDIUM
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /clients/listclients.php. This vulnerability allows attackers to execute arbit
Dec 2, 20225.432NOYES
CVE-2023-53971HIGH
WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functionality. Attackers can upload a
Dec 22, 20258.829NONO
CVE-2021-41919HIGH
webTareas version 2.4 and earlier allows an authenticated user to arbitrarily upload potentially dangerous files without restrictions. This is working by adding or replacing a pers
Oct 8, 20218.827NONO
CVE-2021-41916HIGH
A Cross-Site Request Forgery (CSRF) vulnerability in webTareas version 2.4 and earlier allows a remote attacker to create a new administrative profile and add a new user to the new
Oct 8, 20218.827NONO
CVE-2023-53972HIGH
WebTareas 2.4 contains a SQL injection vulnerability in the webTareasSID cookie parameter that allows unauthenticated attackers to manipulate database queries. Attackers can exploi
Dec 22, 20257.526NONO
CVE-2021-41920HIGH
webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor
Oct 8, 20217.524NONO
CVE-2020-25733HIGH
webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types.
Sep 18, 20207.523NONO
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
67%
22%
11%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network27 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (37.0%)
Unknown0 (0.0%)
Required17 (63.0%)
Privileges Required
Low17 (63.0%)
High0 (0.0%)
None10 (37.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
11.1% of CVEs· 96th percentile
ExploitDB
1 CVE
3.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Webtareas Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Webtareas Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Webtareas Project's Products

View all 2 CNAs →

Top CWEs