N/A
2026-02-17< 5.0.3
Taskbuilder <= 5.0.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Project/Task Comment Creation
Minimum safe version
5.0.4
Update to 5.0.4 or later to address 11 fixable vulnerabilities
Taskbuilder <= 5.0.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Project/Task Comment Creation
Taskbuilder <= 5.0.2 - Authenticated (Subscriber+) SQL Injection via 'order' and 'sort_by' Parameters
Taskbuilder <= 5.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Block Emails' Field
CVE-2025-67933
CVE-2025-30945
Taskbuilder <= 3.0.8 - Authenticated (Admin+) SQL Injection
CVE-2025-39569
CVE-2025-22716
CVE-2024-11930
CVE-2024-9828
CVE-2022-3137