Vulnerabilities > Zephyr ONE > Zephyr Project Manager > 3.2.52

DATE CVE VULNERABILITY TITLE RISK
2024-08-26 CVE-2024-43915 Cross-site Scripting vulnerability in Zephyr-One Zephyr Project Manager
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager allows Reflected XSS.This issue affects Zephyr Project Manager: from n/a through .3.102.
network
low complexity
zephyr-one CWE-79
5.4
2024-08-18 CVE-2024-43322 Authorization Bypass Through User-Controlled Key vulnerability in Zephyr-One Zephyr Project Manager
Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.100.
network
low complexity
zephyr-one CWE-639
critical
9.8
2024-08-03 CVE-2024-7356 Cross-site Scripting vulnerability in Zephyr-One Zephyr Project Manager
The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘filename’ parameter in all versions up to, and including, 3.3.100 due to insufficient input sanitization and output escaping.
network
low complexity
zephyr-one CWE-79
5.4
2024-08-01 CVE-2024-38761 Unspecified vulnerability in Zephyr-One Zephyr Project Manager
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.99.
network
low complexity
zephyr-one
7.5
2024-07-09 CVE-2024-37484 Unspecified vulnerability in Zephyr-One Zephyr Project Manager
Improper Privilege Management vulnerability in Dylan James Zephyr Project Manager allows Privilege Escalation.This issue affects Zephyr Project Manager: from n/a through 3.3.97.
network
low complexity
zephyr-one
8.8
2022-10-03 CVE-2022-2839 Unspecified vulnerability in Zephyr-One Zephyr Project Manager
The Zephyr Project Manager WordPress plugin before 3.2.55 does not have any authorisation as well as CSRF in all its AJAX actions, allowing unauthenticated users to call them either directly or via CSRF attacks.
network
low complexity
zephyr-one
5.4