Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Leantime — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in Leantime, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security weaknesses associated with Leantime, a popular open-source project management software developed by Leantime LLC, primarily focusing on Common Weakness Enumeration (CWE) classifications. It compiles a comprehensive list of identified vulnerabilities, including but not limited to improper input validation, privilege escalation, and cross-site scripting flaws, covering reported issues from the initial releases through recent security advisories. By reviewing this aggregated data, researchers and administrators can track vendor responses to specific advisories, gain a deeper understanding of common vulnerability classes affecting the platform, and analyze the historical vulnerability profile of Leantime to assess its current security posture. The collection serves as a resource for system maintainers who need to identify outdated versions or unpatched components that may pose a risk to their deployment environments. It does not provide real-time monitoring or automated patching solutions, but rather offers a static reference for historical and disclosed security incidents. Users are encouraged to cross-reference these entries with official vendor announcements and independent security databases to verify the status of specific fixes. This page is intended for informational purposes to help teams prioritize their security audits and remediation efforts based on known issues. It reflects the cumulative knowledge of publicly disclosed weaknesses without endorsing any specific mitigation strategy beyond standard patch management practices.

Vendor: Leantime

CVE ID Title CVSS Severity Published
CVE-2026-94211 Hyve5 Leantime Project Dashboard show.blade.php cross site scripting CWE-79 2.4 Low 2026-09-21
CVE-2026-94210 Hyve5 Leantime Kanban Board Tickets.php getAllGrouped cross site scripting CWE-79 3.5 Low 2026-09-21
CVE-2026-92772 Leantime before 3.9.6 Unauthorized Plugin Installation via HTMX CWE-862 7.1 High 2026-09-16
CVE-2026-54418 Leantime - Missing Authorization on TwoFA JSON-RPC Methods Allows Cross-Account 2FA Secret Disclosure and Bypass CWE-862 8.1 High 2026-08-05
CVE-2026-66416 Leantime CSRF Protection Globally Disabled by Omission of Laravel VerifyCsrfToken Middleware CWE-352 8.8 High 2026-07-30
CVE-2026-66415 Leantime Server-Side Request Forgery and Local File Inclusion in Blueprints::import() CWE-918 8.5 High 2026-07-30
CVE-2026-66414 Leantime Open Redirect in Login Controller via redirectUrl Parameter CWE-601 6.1 Medium 2026-07-30
CVE-2026-66412 Leantime all versions prior to and 3.6.2 Broken Access Control via tickets.getMilestone JSON-RPC CWE-639 6.5 Medium 2026-07-27
CVE-2026-15510 Leantime API saveSetting improper authorization CWE-285 6.3 Medium 2026-07-12
CVE-2026-15509 Leantime JSON-RPC Endpoint addUser improper authorization CWE-285 6.3 Medium 2026-07-12
CVE-2026-59712 Leantime - JSON-RPC API Broken Access Control via users.getUser CWE-639 8.1 High 2026-07-06
CVE-2026-59713 Leantime - OIDC Login CSRF via Unconditional State Verification Stub CWE-352 8.1 High 2026-07-06
CVE-2023-45826 Authenticated SQL Injection in leantime CWE-89 6.5 Medium 2023-10-19
CVE-2023-33961 Leantime Stored Cross-site Scripting Vulnerability CWE-79 8.9 High 2023-05-30
CVE-2020-5292 Time-based blind injection in Leantime CWE-89 8.7 High 2020-03-31

All 15 known CVE vulnerabilities affecting Leantime with full Chinese analysis, references, and POCs where available.