Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Priority — Vulnerabilities & Security Advisories 23

Browse all 23 CVE security advisories affecting Priority. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Priority is a task management and productivity platform designed for team collaboration and workflow organization. Historically, Priority has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting (XSS) flaws, and privilege escalation issues, with 14 CVEs documented to date. The platform's security posture has been compromised through insufficient input validation and improper access controls, leading to potential unauthorized system access and data exposure. While no major public security incidents have been widely reported, the consistent pattern of vulnerabilities in web application components suggests ongoing challenges in secure coding practices, requiring organizations to implement robust compensating controls when deploying this solution.

CVE ID Title CVSS Severity Published
CVE-2026-59507 Priority – CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control — Portal Generator addon to Priority ERP (developed by Soft Solutions) CWE-798 9.3 Critical 2026-08-13
CVE-2026-59506 Priority – CWE-306: Missing Authentication for Critical Function — Portal Generator addon to Priority ERP (developed by Soft Solutions) CWE-306 9.3 Critical 2026-08-13
CVE-2026-59505 Priority - CWE-284: Improper Access Control — Portal Generator addon to Priority ERP (developed by Soft Solutions) CWE-284 8.6 High 2026-08-13
CVE-2026-59504 Priority – CWE-602: Client-Side Enforcement of Server-Side Security — Portal Generator addon to Priority ERP (developed by Soft Solutions) CWE-602 9.1 Critical 2026-08-13
CVE-2026-59503 Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor — Portal Generator addon to Priority ERP (developed by Soft Solutions) CWE-200 9.1 Critical 2026-08-13
CVE-2026-59502 Priority - CWE-203: Observable Discrepancy — Portal Generator addon to Priority ERP (developed by Soft Solutions) CWE-203 5.3 Medium 2026-08-13
CVE-2026-59501 Priority – CWE-284: Improper Access Control — Portal Generator addon to Priority ERP (developed by Soft Solutions) CWE-284 8.2 High 2026-08-13
CVE-2026-59500 Priority - CWE-287: Improper Authentication — Portal Generator addon to Priority ERP (developed by Soft Solutions) CWE-287 10.0 Critical 2026-08-13
CVE-2026-59499 Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor — Portal Generator addon to Priority ERP (developed by Soft Solutions). CWE-200 8.6 High 2026-08-13
CVE-2025-55064 Priority - CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') — Web CWE-79 4.8 Medium 2025-12-29
CVE-2025-55063 Priority - CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') — Web CWE-79 4.8 Medium 2025-12-29
CVE-2025-55062 Priority - CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') — Web CWE-79 4.8 Medium 2025-12-29
CVE-2025-55061 Priority - CWE-434 Unrestricted Upload of File with Dangerous Type — Web CWE-434 8.8 High 2025-12-29
CVE-2025-55060 Priority - CWE-601: URL Redirection to Untrusted Site ('Open Redirect') — Web CWE-601 6.1 Medium 2025-12-29
CVE-2024-47922 Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor — PRI WEB CWE-200 7.5 High 2024-12-30
CVE-2024-41699 Priority – CWE-552: Files or Directories Accessible to External Parties — Priority CWE-552 4.4 Medium 2024-08-20
CVE-2024-41698 Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor — Priority CWE-200 4.3 Medium 2024-08-20
CVE-2024-41697 Priority – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) — Priority CWE-80 6.1 Medium 2024-08-20
CVE-2024-41696 Priority PRI WEB Portal Add-On for Priority ERP on prem – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor — PRI WEB Portal Add-On for Priority ERP on prem CWE-200 7.5 High 2024-07-30
CVE-2023-23460 Priority Web – Authentication bypass — Priority Web 9.1 Critical 2023-02-15
CVE-2023-23459 Priority Windows – Command Execution via SQL Injection — Priority for Windows CWE-89 9.1 Critical 2023-02-15
CVE-2022-23173 Priority - Priority web Insecure direct object references (IDOR) — Priority web 5.5 Medium 2022-07-06
CVE-2022-23172 Priority - Priority User Enumeration — Priority 5.5 Medium 2022-07-06

This page lists every published CVE security advisory associated with Priority. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.