Taskbuilder
Taskbuilder is a WordPress component with 16 published CVE records in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 8.5.
taskbuilderCVE-2026-15267: Taskbuilder subscribers can inject SQL through project filtering
Taskbuilder through 5.0.9 exposes the authenticated wppm_view_project_tasks AJAX action without a capability check beyond having a WordPress account. The request's wppm_proj_filter value can be re-read with only sanitize_text_field(), concatenated as an unquoted operand into Task.project, and embedded in the query instead of being passed as a $wpdb->prepare() argument. A Subscriber can therefore alter the query and extract sensitive database information. The CNA record does not identify the precise database contents obtainable. Version 6.0.0 casts the value with absint() and binds it with a %d placeholder.
| Safe version |
|
||
|---|---|---|---|
| Jul 28, 2026 |
CVE-2026-15267
Taskbuilder subscribers can inject SQL through project filtering
Taskbuilder through 5.0.9 exposes the authenticated wppm_view_project_tasks AJAX action without a capability check beyond having a WordPress account. The request's wppm_proj_filter value can be re-read with only sanitize_text_field(), concatenated as an unquoted operand into Task.project, and embedded in the query instead of being passed as a $wpdb->prepare() argument. A Subscriber can therefore alter the query and extract sensitive database information. The CNA record does not identify the precise database contents obtainable. Version 6.0.0 casts the value with absint() and binds it with a %d placeholder.
|
6.0.0 |
CVE6.5
NVDPending
|
| Jul 01, 2026 |
CVE-2026-12110
Taskbuilder – Project Management & Task Management Tool With Kanban Board: SQL injection
Taskbuilder – Project Management & Task Management Tool With Kanban Board is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 5.0.8.
|
> 5.0.8 |
CVE6.5
NVDPending
|
| Jul 01, 2026 |
CVE-2026-12090
Taskbuilder – Project Management & Task Management Tool With Kanban Board: SQL injection
Taskbuilder – Project Management & Task Management Tool With Kanban Board is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 5.0.8.
|
> 5.0.8 |
CVE6.5
NVDPending
|
| Jun 17, 2026 |
CVE-2026-9570
Taskbuilder: Cross-site scripting
Taskbuilder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is < 5.0.8.
|
5.0.8 |
CVE7.1
NVDPending
|
| Jun 15, 2026 |
CVE-2026-52697
Taskbuilder: SQL injection
Taskbuilder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 5.0.7.
|
5.0.8 |
CVE8.5
NVDPending
|
| Mar 04, 2026 |
CVE-2026-2289
Taskbuilder: Cross-site scripting
Taskbuilder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.4
NVDPending
|
| Feb 18, 2026 |
CVE-2026-1640
Taskbuilder – WordPress Project Management & Task Management: A security weakness
Taskbuilder – WordPress Project Management & Task Management is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Feb 18, 2026 |
CVE-2026-1639
Taskbuilder – WordPress Project Management & Task Management: SQL injection
Taskbuilder – WordPress Project Management & Task Management is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jan 08, 2026 |
CVE-2025-67933
Taskbuilder: Cross-site scripting
Taskbuilder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Jun 06, 2025 |
CVE-2025-30945
Taskbuilder: A security weakness
Taskbuilder is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| May 15, 2025 |
CVE-2024-9831
Taskbuilder: SQL injection
Taskbuilder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Apr 17, 2025 |
CVE-2025-39569
Taskbuilder: SQL injection
Taskbuilder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVDPending
|
| Jan 21, 2025 |
CVE-2025-22716
Taskbuilder: SQL injection
Taskbuilder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVD8.8
|
| Jan 04, 2025 |
CVE-2024-11930
Taskbuilder – WordPress Project & Task Management plugin: Cross-site scripting
Taskbuilder – WordPress Project & Task Management plugin is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Nov 21, 2024 |
CVE-2024-9828
Taskbuilder: SQL injection
Taskbuilder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE4.1
NVDPending
|
| Oct 10, 2022 |
CVE-2022-3137
Taskbuilder: Cross-site scripting
Taskbuilder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|