CVE-2020-25735: Webtareas Project Webtareas

Medium severity, CVSS 6.1. EPSS: 1.4% chance of exploitation in the next 30 days.

webTareas through 2.1 allows XSS in clients/editclient.php, extensions/addextension.php, administration/add_announcement.php, administration/departments.php, administration/locations.php, expenses/claim_type.php, projects/editproject.php, and general/newnotifications.php.

Affected products

Published 2020-09-18. Last modified 2026-06-17.