Browse all 23 CVE security advisories affecting Priority. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Priority is a task management and productivity platform designed for team collaboration and workflow organization. Historically, Priority has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting (XSS) flaws, and privilege escalation issues, with 14 CVEs documented to date. The platform's security posture has been compromised through insufficient input validation and improper access controls, leading to potential unauthorized system access and data exposure. While no major public security incidents have been widely reported, the consistent pattern of vulnerabilities in web application components suggests ongoing challenges in secure coding practices, requiring organizations to implement robust compensating controls when deploying this solution.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-59507 | Priority – CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control — Portal Generator addon to Priority ERP (developed by Soft Solutions) CWE-798 | 9.3 | Critical | 2026-08-13 |
| CVE-2026-59506 | Priority – CWE-306: Missing Authentication for Critical Function — Portal Generator addon to Priority ERP (developed by Soft Solutions) CWE-306 | 9.3 | Critical | 2026-08-13 |
| CVE-2026-59505 | Priority - CWE-284: Improper Access Control — Portal Generator addon to Priority ERP (developed by Soft Solutions) CWE-284 | 8.6 | High | 2026-08-13 |
| CVE-2026-59504 | Priority – CWE-602: Client-Side Enforcement of Server-Side Security — Portal Generator addon to Priority ERP (developed by Soft Solutions) CWE-602 | 9.1 | Critical | 2026-08-13 |
| CVE-2026-59503 | Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor — Portal Generator addon to Priority ERP (developed by Soft Solutions) CWE-200 | 9.1 | Critical | 2026-08-13 |
| CVE-2026-59502 | Priority - CWE-203: Observable Discrepancy — Portal Generator addon to Priority ERP (developed by Soft Solutions) CWE-203 | 5.3 | Medium | 2026-08-13 |
| CVE-2026-59501 | Priority – CWE-284: Improper Access Control — Portal Generator addon to Priority ERP (developed by Soft Solutions) CWE-284 | 8.2 | High | 2026-08-13 |
| CVE-2026-59500 | Priority - CWE-287: Improper Authentication — Portal Generator addon to Priority ERP (developed by Soft Solutions) CWE-287 | 10.0 | Critical | 2026-08-13 |
This page lists every published CVE security advisory associated with Priority. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.