CVE-2020-25735: Webtareas Project Webtareas
Medium severity, CVSS 6.1. EPSS: 1.4% chance of exploitation in the next 30 days.
webTareas through 2.1 allows XSS in clients/editclient.php, extensions/addextension.php, administration/add_announcement.php, administration/departments.php, administration/locations.php, expenses/claim_type.php, projects/editproject.php, and general/newnotifications.php.
Affected products
- Webtareas Project Webtareas: up to and including 2.1
Published 2020-09-18. Last modified 2026-06-17.