Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

ProjectSend — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in ProjectSend, with AI-generated Chinese analysis, references, and POCs.

This page documents vulnerability aggregations for ProjectSend, a vendor-managed file sharing application, focusing on weakness types such as cross-site scripting and insecure direct object references within the Common Weakness Enumeration framework. It collects security advisories, bug reports, and exploit details spanning from the product’s initial public release through recent patches, ensuring a comprehensive historical view of its security posture. Here, users can track the vendor’s response timeline to critical issues, understand the evolution and prevalence of specific weakness classes affecting file management software, and look up a product's vulnerability history to assess risk exposure over time. The data includes technical details about affected versions, patch release dates, and the nature of the exploits without endorsing or facilitating their use. By aggregating sources from security researchers, CERT teams, and the vendor itself, this resource provides a neutral, factual record of security incidents. It serves developers, security auditors, and IT administrators seeking to evaluate the reliability of ProjectSend or compare it against similar applications in terms of remediation speed and transparency. No specific CVE identifiers are highlighted in this overview, but detailed records are available for each listed incident. The information is strictly for defensive security analysis and educational purposes, helping stakeholders make informed decisions about software procurement and patch management strategies.

Vendor: unspecified

CVE ID Title CVSS Severity Published
CVE-2026-53992 Reflected XSS in ProjectSend thumbnails-regenerate.php via start_date / end_date Parameters CWE-79 6.1 Medium 2026-08-05
CVE-2021-47947 Projectsend r1295 Stored Cross-Site Scripting via files-edit.php CWE-79 6.4 Medium 2026-05-10
CVE-2026-5624 ProjectSend upload.php cross-site request forgery CWE-352 4.3 Medium 2026-04-06
CVE-2026-4045 projectsend Auth.php response discrepancy CWE-204 3.7 Low 2026-03-12
CVE-2026-4044 projectsend Delete import-orphans.php realpath path traversal CWE-22 3.8 Low 2026-03-12
CVE-2026-3977 projectsend AJAX Endpoints authorization CWE-862 6.3 Medium 2026-03-12
CVE-2023-53980 ProjectSend r1605 Remote Code Execution via File Extension Manipulation CWE-434 9.8 Critical 2025-12-22
CVE-2023-53930 ProjectSend r1605 Insecure Direct Object Reference File Download Vulnerability CWE-639 7.5 High 2025-12-17
CVE-2023-53905 ProjectSend r1605 CSV Injection via User Account Export Functionality CWE-1236 8.0 High 2025-12-17
CVE-2023-53906 ProjectSend r1605 Stored Cross-Site Scripting via Custom Assets Page CWE-79 4.8 Medium 2025-12-17
CVE-2025-13232 projectsend File Editor/Custom Download Aliases cross site scripting CWE-79 3.5 Low 2025-11-16
CVE-2024-11680 ProjectSend Unauthenticated Configuration Modification CWE-306 9.8 Critical 2024-11-26
CVE-2024-7659 projectsend Password Reset Token functions.php generate_random_string random values CWE-330 3.7 Low 2024-08-11
CVE-2024-7658 projectsend process.php get_preview resource injection CWE-99 5.3 Medium 2024-08-11
CVE-2017-20101 ProjectSend information disclosure CWE-200 3.5 Low 2022-06-27

All 15 known CVE vulnerabilities affecting ProjectSend with full Chinese analysis, references, and POCs where available.