Taskbuilder <= 5.0.9 - Authenticated (Subscriber+) SQL Injection
medium
The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL Injection via the 'wppm_proj_filter' parameter in versions up to, and including, 5.0.9. This is due to insufficient escaping on the user-supplied parameter and the lack of sufficient preparation on th...
- CVSS:
- 6.5
- Affected:
- up to 5.0.9
- Fixed in:
- 6.0.0
- Disclosed:
- Jul 27, 2026
CVE-2026-15267 on NVD →
Taskbuilder <= 5.0.8 - Authenticated (Subscriber+) SQL Injection via 'task_search' Parameter
medium
The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to generic SQL Injection via the 'task_search' parameter in all versions up to, and including, 5.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exis...
- CVSS:
- 6.5
- Affected:
- up to 5.0.8
- Fixed in:
- 5.0.9
- Disclosed:
- Jun 30, 2026
CVE-2026-12110 on NVD →
Taskbuilder <= 5.0.8 - Authenticated (Subscriber+) SQL Injection via 'wppm_proj_filter' Parameter
medium
The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to generic SQL Injection via the 'wppm_proj_filter' parameter in all versions up to, and including, 5.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the...
- CVSS:
- 6.5
- Affected:
- up to 5.0.8
- Fixed in:
- 5.0.9
- Disclosed:
- Jun 30, 2026
CVE-2026-12090 on NVD →
Taskbuilder – Project Management & Task Management Tool With Kanban Board <= 5.0.7 - Authenticated (Subscriber+) SQL Injection
medium
The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for a...
- CVSS:
- 6.5
- Affected:
- up to 5.0.7
- Fixed in:
- 5.0.8
- Disclosed:
- Jun 10, 2026
CVE-2026-52697 on NVD →
Taskbuilder – Project Management & Task Management Tool With Kanban Board <= 5.0.6 - Authenticated (Subscriber+) Time-Based Blind SQL Injection via 'project_search' Parameter
medium
The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'project_search' parameter in all versions up to, and including, 5.0.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation...
- CVSS:
- 6.5
- Affected:
- up to 5.0.6
- Fixed in:
- 5.0.7
- Disclosed:
- May 13, 2026
CVE-2026-6225 on NVD →
Taskbuilder - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Block Emails' Field vulnerability
medium
Authenticated (Administrator+) Stored Cross-Site Scripting via 'Block Emails' Field vulnerability
- CVSS:
- 5.9
- Affected:
- up to 5.0.3
- Fixed in:
- 5.0.4
- Disclosed:
- Mar 3, 2026
Taskbuilder <= 5.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Block Emails' Field
medium
The Taskbuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbit...
- CVSS:
- 4.4
- Affected:
- up to 5.0.3
- Fixed in:
- 5.0.4
- Disclosed:
- Mar 3, 2026
CVE-2026-2289 on NVD →
Taskbuilder <= 5.0.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Project/Task Comment Creation
medium
The Taskbuilder – WordPress Project Management & Task Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.0.2. This is due to missing authorization checks on the project and task comment submission functions (AJAX actions: wppm_submit_proj_comment and wppm_submi...
- CVSS:
- 4.3
- Affected:
- up to 5.0.2
- Fixed in:
- 5.0.3
- Disclosed:
- Feb 17, 2026
CVE-2026-1640 on NVD →
Taskbuilder <= 5.0.2 - Authenticated (Subscriber+) SQL Injection via 'order' and 'sort_by' Parameters
medium
The Taskbuilder – WordPress Project Management & Task Management plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order' and 'sort_by' parameters in all versions up to, and including, 5.0.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the...
- CVSS:
- 6.5
- Affected:
- up to 5.0.2
- Fixed in:
- 5.0.3
- Disclosed:
- Feb 17, 2026
CVE-2026-1639 on NVD →
Taskbuilder – WordPress Project Management & Task Management [taskbuilder] <= 4.0.9 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in taskbuilder Taskbuilder taskbuilder allows Reflected XSS.This issue affects Taskbuilder: from n/a through <= 4.0.9.
- Affected:
- up to 4.0.9
- Fix:
- No patched version reported
- Disclosed:
- Jan 8, 2026
CVE-2025-67933 on NVD →
Taskbuilder <= 4.0.9 - Reflected Cross-Site Scripting
medium
The Taskbuilder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tri...
- CVSS:
- 6.1
- Affected:
- up to 4.0.9
- Fixed in:
- 5.0.0
- Disclosed:
- Jan 6, 2026
CVE-2025-67933 on NVD →
Taskbuilder – WordPress Project Management & Task Management [taskbuilder] <= 4.0.3 (unfixed)
unknown
[en] Missing Authorization vulnerability in taskbuilder Taskbuilder allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Taskbuilder: from n/a through 4.0.3.
- Affected:
- up to 4.0.3
- Fix:
- No patched version reported
- Disclosed:
- Jun 6, 2025
CVE-2025-30945 on NVD →
Taskbuilder <= 4.0.7 - Missing Authorization
medium
The Taskbuilder – WordPress Project & Task Management plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.0.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.0.7
- Fixed in:
- 4.0.8
- Disclosed:
- Jun 5, 2025
CVE-2025-30945 on NVD →
Taskbuilder <= 4.0.1 - Authenticated (Subscriber+) SQL Injection
medium
The Taskbuilder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and abov...
- CVSS:
- 6.5
- Affected:
- up to 4.0.1
- Fixed in:
- 4.0.2
- Disclosed:
- Apr 17, 2025
CVE-2025-39569 on NVD →
Taskbuilder – WordPress Project Management & Task Management [taskbuilder] < 4.0.2
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in taskbuilder Taskbuilder allows Blind SQL Injection. This issue affects Taskbuilder: from n/a through 4.0.1.
- Affected:
- up to 4.0.2
- Fixed in:
- 4.0.2
- Disclosed:
- Apr 17, 2025
CVE-2025-39569 on NVD →
Taskbuilder <= 3.0.8 - Authenticated (Admin+) SQL Injection
medium
The Taskbuilder – WordPress Project & Task Management plugin plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated...
- CVSS:
- 4.9
- Affected:
- up to 3.0.8
- Fixed in:
- 3.0.9
- Disclosed:
- Mar 3, 2025
CVE-2024-9831 on NVD →
Taskbuilder – WordPress Project Management & Task Management [taskbuilder] < 3.0.7
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Taskbuilder Team Taskbuilder allows SQL Injection. This issue affects Taskbuilder: from n/a through 3.0.6.
- Affected:
- up to 3.0.7
- Fixed in:
- 3.0.7
- Disclosed:
- Jan 21, 2025
CVE-2025-22716 on NVD →
Taskbuilder <= 3.0.6 - Authenticated (Subscriber+) SQL Injection
medium
The Taskbuilder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and abov...
- CVSS:
- 6.5
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.7
- Disclosed:
- Jan 15, 2025
CVE-2025-22716 on NVD →
Taskbuilder – WordPress Project Management & Task Management [taskbuilder] < 3.0.7
unknown
[en] The Taskbuilder – WordPress Project & Task Management plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppm_tasks shortcode in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it poss...
- Affected:
- up to 3.0.7
- Fixed in:
- 3.0.7
- Disclosed:
- Jan 4, 2025
CVE-2024-11930 on NVD →
Taskbuilder – WordPress Project & Task Management plugin <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via wppm_tasks Shortcode
medium
The Taskbuilder – WordPress Project & Task Management plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppm_tasks shortcode in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible...
- CVSS:
- 6.4
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.7
- Disclosed:
- Jan 3, 2025
CVE-2024-11930 on NVD →
Taskbuilder – WordPress Project Management & Task Management [taskbuilder] < 3.0.5
unknown
[en] The Taskbuilder WordPress plugin before 3.0.5 does not sanitize user input into the 'load_orders' parameter and uses it in a SQL statement, allowing high privilege users such as admin to perform SQL Injection attacks
- Affected:
- up to 3.0.5
- Fixed in:
- 3.0.5
- Disclosed:
- Nov 21, 2024
CVE-2024-9828 on NVD →
Taskbuilder – WordPress Project & Task Management plugin <= 3.0.4 - Authenticated (Admin+) SQL injection
medium
The Taskbuilder – WordPress Project & Task Management plugin plugin for WordPress is vulnerable to SQL Injection via the 'load_orders' parameter in all versions up to, and including, 3.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This mak...
- CVSS:
- 4.9
- Affected:
- up to 3.0.4
- Fixed in:
- 3.0.5
- Disclosed:
- Oct 31, 2024
CVE-2024-9828 on NVD →
Taskbuilder – WordPress Project Management & Task Management [taskbuilder] < 1.0.8
unknown
[en] The Taskbuilder WordPress plugin before 1.0.8 does not validate and sanitise task's attachments, which could allow any authenticated user (such as subscriber) creating a task to perform Stored Cross-Site Scripting by attaching a malicious SVG file
- Affected:
- up to 1.0.8
- Fixed in:
- 1.0.8
- Disclosed:
- Oct 10, 2022
CVE-2022-3137 on NVD →
Taskbuilder <= 1.0.7 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The Taskbuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject arbitrary w...
- CVSS:
- 6.4
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.8
- Disclosed:
- Sep 15, 2022
CVE-2022-3137 on NVD →
Taskbuilder – WordPress Project Management & Task Management [taskbuilder] < 3.0.9
unknown
- Affected:
- up to 3.0.9
- Fixed in:
- 3.0.9
CVE-2024-9831 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database