CVE-2025-12496
Zephyr Project Manager
Minimum safe version
3.3.204
Update to 3.3.204 or later to address 25 fixable vulnerabilities
Zephyr Project Manager <= 3.3.202 - Authenticated (Admin+) Stored Cross-Site Scripting
CVE-2025-54714
CVE-2025-39552
CVE-2025-32526
CVE-2024-43916
CVE-2024-43915
CVE-2024-43322
CVE-2024-7624
WordPress Zephyr Project Manager Plugin <= 3.3.100 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-6536
CVE-2024-38761
CVE-2024-37484
CVE-2023-34373
Zephyr Project Manager < 3.2.5 - Unauthorised REST Calls to Stored XSS
Zephyr Project Manager < 3.2.5 - Reflected Cross-Site Scripting
CVE-2023-31237
Zephyr Project Manager <= 3.2.42 - Missing Authorization to Cross-Site Scripting
Zephyr Project Manager <= 3.2.42 - Reflected Cross-Site Scripting
CVE-2022-2839
CVE-2022-3333
WordPress Zephyr Project Manager plugin <= 3.2.42 - Reflected Cross-Site Scripting (XSS) vulnerability
WordPress Zephyr Project Manager plugin <= 3.2.42 - Unauthorized REST Calls to Stored Cross-Site Scripting (XSS) vulnerability
CVE-2022-2840
CVE-2022-1822