Known Vulnerabilities for Leantime by Leantime
Listed below are 3 of the newest known vulnerabilities associated with "Leantime" by "Leantime".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-66416 json | Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-cha... | Not Provided | 2026-07-30 | 2026-07-31 |
| CVE-2026-66415 json | Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attack... | Not Provided | 2026-07-30 | 2026-07-31 |
| CVE-2026-66414 json | Leantime 3.6.2 contains an open redirect vulnerability in the Login controller that allows unauthenticated attackers to redir... | Not Provided | 2026-07-30 | 2026-07-31 |
| CVE-2026-66412 json | Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone dat... | Not Provided | 2026-07-27 | 2026-07-28 |
| CVE-2026-59713 json | Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without vali... | Not Provided | 2026-07-06 | 2026-07-07 |
| CVE-2026-59712 json | Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to retri... | Not Provided | 2026-07-06 | 2026-07-07 |
| CVE-2026-15510 json | A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. The ma... | Not Provided | 2026-07-12 | 2026-07-13 |
| CVE-2026-15509 json | A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON-RPC ... | Not Provided | 2026-07-12 | 2026-07-15 |
| CVE-2023-45826 json | Leantime is an open source project management system. A 'userId' variable in `app/domain/files/repositories/class.files.php` ... | 6.5 - MEDIUM | 2023-10-19 | 2023-10-27 |
| CVE-2023-33961 json | Leantime is a lean open source project management system. Starting in version 2.3.21, an authenticated user with commenting p... | 5.4 - MEDIUM | 2023-05-30 | 2023-06-06 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Leantime | Leantime | 2.1 | |||
| Application | Leantime | Leantime | 2.1 | |||
| Application | Leantime | Leantime | 2.1 | |||
| Application | Leantime | Leantime | 2.1 | |||
| Application | Leantime | Leantime | 2.1 | |||
| Application | Leantime | Leantime | 2.1 | |||
| Application | Leantime | Leantime | 2.0.9 | |||
| Application | Leantime | Leantime | 2.0.8 | |||
| Application | Leantime | Leantime | 2.0.7 | |||
| Application | Leantime | Leantime | 2.0.6 | |||
| Application | Leantime | Leantime | 2.0.5 | |||
| Application | Leantime | Leantime | 2.0.4 | |||
| Application | Leantime | Leantime | 2.0.3 | |||
| Application | Leantime | Leantime | 2.0.2 | |||
| Application | Leantime | Leantime | 2.0.15 | |||
| Application | Leantime | Leantime | 2.0.14 | |||
| Application | Leantime | Leantime | 2.0.13 | |||
| Application | Leantime | Leantime | 2.0.12 | |||
| Application | Leantime | Leantime | 2.0.11 | |||
| Application | Leantime | Leantime | 2.0.10 |