Vulnerabilities > Zephyr ONE > Zephyr Project Manager

DATE CVE VULNERABILITY TITLE RISK
2022-10-03 CVE-2022-2839 Cross-site Scripting vulnerability in Zephyr-One Zephyr Project Manager
The Zephyr Project Manager WordPress plugin before 3.2.55 does not have any authorisation as well as CSRF in all its AJAX actions, allowing unauthenticated users to call them either directly or via CSRF attacks.
network
low complexity
zephyr-one CWE-79
5.4
2022-09-28 CVE-2022-3333 Improper Enforcement of Message or Data Structure vulnerability in Zephyr-One Zephyr Project Manager
A vulnerability, which was classified as problematic, was found in Zephyr Project Manager up to 3.2.4.
network
low complexity
zephyr-one CWE-707
5.4