Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Bdtask — Vulnerabilities & Security Advisories 37

Browse all 37 CVE security advisories affecting Bdtask. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Bdtask operates as a business process automation platform, primarily serving enterprises that require robust workflow orchestration and task scheduling capabilities. Despite its utility in streamlining operations, the software has faced significant scrutiny due to a high volume of disclosed security flaws, with thirty-five Common Vulnerabilities and Exposures (CVEs) currently on record. Historically, these vulnerabilities predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from inadequate input validation and insufficient access controls within the application’s architecture. Notable incidents include critical exploits allowing unauthenticated attackers to execute arbitrary commands on affected servers, highlighting systemic weaknesses in the product’s security design. These recurring issues underscore the necessity for rigorous patch management and continuous security auditing for organizations relying on this automation infrastructure to mitigate potential data breaches and service disruptions.

CVE ID Title CVSS Severity Published
CVE-2026-10172 Bdtask Multi-Store Inventory Management System Component Module.php upload unrestricted upload — Multi-Store Inventory Management System CWE-434 6.3 Medium 2026-05-31
CVE-2026-10155 Bdtask Multi-Store Inventory Management System Accounts Report Accounts.php accounts_report_search sql injection — Multi-Store Inventory Management System CWE-89 4.7 Medium 2026-05-30
CVE-2019-25505 Tradebox 5.4 SQL Injection via symbol Parameter — Tradebox CWE-89 7.1 High 2026-03-04
CVE-2020-37106 Business Live Chat Software 1.0 - Cross-Site Request Forgery (Add Admin) — Business Live Chat Software CWE-352 5.3 Medium 2026-02-06
CVE-2026-1600 Bdtask Bhojon All-In-One Restaurant Management System Add-to-Cart Submission Endpoint addtocart logic error — Bhojon All-In-One Restaurant Management System CWE-840 4.3 Medium 2026-01-29
CVE-2026-1599 Bdtask Bhojon All-In-One Restaurant Management System Checkout placeorder logic error — Bhojon All-In-One Restaurant Management System CWE-840 4.3 Medium 2026-01-29
CVE-2026-1598 Bdtask Bhojon All-In-One Restaurant Management System User Information profile cross site scripting — Bhojon All-In-One Restaurant Management System CWE-79 3.5 Low 2026-01-29
CVE-2026-1597 Bdtask SalesERP Administrative Endpoint improper authorization — SalesERP CWE-285 6.3 Medium 2026-01-29
CVE-2025-40679 HTML injection in Isshue from Bdtask — Isshue CWE-79 7.2AI High AI 2026-01-20
CVE-2021-47769 Isshue Shopping Cart 3.5 - 'Title' Cross Site Scripting (XSS) — Isshue Shopping Cart CWE-79 4.8 Medium 2026-01-15
CVE-2025-13239 Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution submit_checkout behavioral workflow — Isshue Multi Store eCommerce Shopping Cart Solution CWE-841 4.3 Medium 2025-11-16
CVE-2025-13238 Bdtask Flight Booking Software Edit Profile edit unrestricted upload — Flight Booking Software CWE-434 6.3 Medium 2025-11-16
CVE-2025-13186 Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution manage_customer cross site scripting — Isshue Multi Store eCommerce Shopping Cart Solution CWE-79 2.4 Low 2025-11-14
CVE-2025-13185 Bdtask/CodeCanyon News365 profile unrestricted upload — News365 CWE-434 4.7 Medium 2025-11-14
CVE-2025-13180 Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System edit_profile cross site scripting — Wholesale Inventory Control and Inventory Management System CWE-80 3.5 Low 2025-11-14
CVE-2025-13179 Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System cross-site request forgery — Wholesale Inventory Control and Inventory Management System CWE-352 4.3 Medium 2025-11-14
CVE-2025-13178 Bdtask/CodeCanyon SalesERP User Profile edit_profile cross site scripting — SalesERP CWE-80 3.5 Low 2025-11-14
CVE-2025-13177 Bdtask/CodeCanyon SalesERP cross-site request forgery — SalesERP CWE-352 4.3 Medium 2025-11-14
CVE-2025-12288 Bdtask Pharmacy Management System User Profile edit_user authorization — Pharmacy Management System CWE-639 4.3 Medium 2025-10-27
CVE-2025-12287 Bdtask Wholesale Inventory Control and Inventory Management System edit_profile sql injection — Wholesale Inventory Control and Inventory Management System CWE-89 4.7 Medium 2025-10-27
CVE-2025-12223 Bdtask Flight Booking Software Package Information package-information unrestricted upload — Flight Booking Software CWE-434 6.3 Medium 2025-10-27
CVE-2025-12222 Bdtask Flight Booking Software Deposit deposit unrestricted upload — Flight Booking Software CWE-434 6.3 Medium 2025-10-27
CVE-2024-3151 Bdtask Multi-Store Inventory Management System Stock Movement Page cross-site request forgery — Multi-Store Inventory Management System CWE-352 4.3 Medium 2024-04-02
CVE-2024-2998 Bdtask Multi-Store Inventory Management System Store Update Page cross site scripting — Multi-Store Inventory Management System CWE-79 2.4 Low 2024-03-27
CVE-2024-2997 Bdtask Multi-Store Inventory Management System cross site scripting — Multi-Store Inventory Management System CWE-79 2.4 Low 2024-03-27
CVE-2024-2996 Bdtask Multi-Store Inventory Management System Page Title cross site scripting — Multi-Store Inventory Management System CWE-79 2.4 Low 2024-03-27
CVE-2024-2639 Bdtask Wholesale Inventory Management System session fixiation — Wholesale Inventory Management System CWE-384 4.3 Medium 2024-03-19
CVE-2024-2317 Bdtask Hospital AutoManager Prescription Page improper authorization — Hospital AutoManager CWE-285 3.8 Low 2024-03-08
CVE-2024-2316 Bdtask Hospital AutoManager Update Bill Page cross-site request forgery — Hospital AutoManager CWE-352 4.3 Medium 2024-03-08
CVE-2024-2277 Bdtask G-Prescription Gynaecology & OBS Consultation Software Password Reset change_password_save cross-site request forgery — G-Prescription Gynaecology & OBS Consultation Software CWE-352 4.3 Medium 2024-03-08

This page lists every published CVE security advisory associated with Bdtask. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.