Bounties
Partners
Community
Info
alanaktion / phproject
Project repository
A high performance full-featured project management system
Submit a report
FIRST INTERACTION
WITHIN
N/A DAYS
REVIEW
WITHIN
73 DAYS
FIX
WITHIN
53 DAYS
Cross-site Scripting (XSS)
Jun 13th 2022
iohehe
•
pending
XSS vulnerability can be caused by uploading PDF files where project files are u...
Apr 18th 2022
l0ading-x
•
pending
Bypass Open Redirect fix
Apr 14th 2022
minhnb11
•
pending
Improper Access Control
Mar 29th 2022
tharunavula
•
pending
Improper Access Control
Mar 29th 2022
tharunavula
•
pending
Improper Access Control
Mar 29th 2022
tharunavula
•
pending
security misconfiguration
Mar 29th 2022
tharunavula
•
pending
EXIF Geolocation Data Not Stripped From Uploaded Images (vulnerability)
Mar 29th 2022
tharunavula
•
pending
Improper Access Control
Mar 29th 2022
tharunavula
•
pending
Improper Access Control
Mar 29th 2022
tharunavula
•
pending
Open Redirect
Jul 31st 2022
baharuddinzulkifli
•
self closed
Cross-site Scripting (XSS) - Stored
Mar 22nd 2022
dungtuanha
•
pending
File in issue is not deleted and still be view by access an old url
Mar 22nd 2022
lekhang123lc
•
pending
User can see a task they not assigned or in that task's watcher
Mar 22nd 2022
lekhang123lc
•
pending
Open Redirect still working
Mar 18th 2022
kushagrasarathe
•
pending
Unverified Password Change
Aug 9th 2022
thanhlocstudent
•
self closed
Stored XSS via Popover Bootstrap
Aug 9th 2022
thanhlocstudent
•
self closed
Bypass force downloading files
Aug 9th 2022
thanhlocstudent
•
self closed
Stored xss at logo input field
Mar 17th 2022
thanhtuan1695
•
pending
Open Redirect [Bypass Of #7ed4a3a5-7197-4904-8f88-7bd586dcd060]
Mar 13th 2022
mdakh404
•
pending
Open Redirect
Mar 13th 2022
nhiephon
•
pending
Cross-site Scripting (XSS) - Stored
Mar 12th 2022
nhiephon
•
Medium
•
$5
Medium
•
$5
Improper Access Control
Mar 12th 2022
nhiephon
•
High
•
$10
High
•
$10
Unrestricted Upload of File with Dangerous Type
Mar 12th 2022
nhiephon
•
Medium
•
$10
Medium
•
$10
Cross-site Scripting (XSS) - Stored
Mar 12th 2022
aravindd007
•
Medium
•
$5
Medium
•
$5
Open Redirect
Mar 12th 2022
khanhchauminh
•
Medium
•
$6
Medium
•
$6
Open Redirect
Mar 12th 2022
ranjit-git
•
Medium
•
$7
Medium
•
$7
Open Redirect
Jan 28th 2022
ranjit-git
•
High
•
$25
High
•
$25
Cross-site Scripting (XSS) - Stored
Jan 28th 2022
ranjit-git
•
High
•
$25
High
•
$25
Cross-Site Request Forgery (CSRF)
Sep 10th 2021
am0o0
•
Medium
•
$25
Medium
•
$25
Cross-Site Request Forgery (CSRF)
Sep 10th 2021
am0o0
•
Medium
•
$25
Medium
•
$25
Cross-Site Request Forgery (CSRF)
Sep 10th 2021
am0o0
•
Medium
•
$25
Medium
•
$25
Cross-Site Request Forgery (CSRF)
Sep 10th 2021
am0o0
•
Medium
•
$25
Medium
•
$25
CRITICAL
$0
HIGH
$0
MEDIUM
$0
LOW
$0