CVE-2019-19249: Querytreeapp Querytree

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Controllers/InvitationsController.cs in QueryTree before 3.0.99-beta mishandles invitations.

Affected products

  • Querytreeapp Querytree: version 3.0.11 only; version 3.0.13 only; version 3.0.15 only; version 3.0.17 only; version 3.0.19 only; version 3.0.21 only; …

Published 2019-11-25. Last modified 2026-06-17.