VYPR
Vendor

Bdtask

Products
23
CVEs
41
Across products
59
Status
Private

Products

23

Recent CVEs

41
View all 41 CVEs →
  • CVE-2022-28993CriMay 20, 2022
    risk 0.64cvss 9.8epss 0.02

    Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request.

  • CVE-2022-28991HigMay 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files.

  • CVE-2019-25505HigMar 4, 2026
    risk 0.46cvss 7.1epss 0.00

    Tradebox 5.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the symbol parameter. Attackers can send POST requests to the monthly_deposit endpoint with malicious symbol values using…

  • CVE-2020-13426MedJun 22, 2020
    risk 0.42cvss 6.5epss 0.01

    The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it presents, allowing the possibility of deleting records (users) when an ID is known.

  • CVE-2026-10172MedMay 31, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in Bdtask Multi-Store Inventory Management System 1.0. The affected element is the function Upload of the file application/modules/dashboard/controllers/Module.php of the component Component Module. The manipulation of the argument module…

  • CVE-2026-1597MedJan 29, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in Bdtask SalesERP up to 20260116. This issue affects some unknown processing of the component Administrative Endpoint. Such manipulation of the argument ci_session leads to improper authorization. The attack may be performed from remote. The…

  • CVE-2025-13238MedNov 16, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in Bdtask Flight Booking Software 4. Affected by this vulnerability is an unknown functionality of the file /agent/profile/edit of the component Edit Profile Page. This manipulation causes unrestricted upload. The attack may be initiated remotely.…

  • CVE-2025-12223MedOct 27, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in Bdtask Flight Booking Software up to 3.1. This affects an unknown part of the file /b2c/package-information of the component Package Information Module. The manipulation results in unrestricted upload. The attack can be launched remotely. The…

  • CVE-2025-12222MedOct 27, 2025
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in Bdtask Flight Booking Software up to 3.1. Affected by this issue is some unknown functionality of the file /admin/transaction/deposit of the component Deposit Handler. The manipulation leads to unrestricted upload. The attack can be…

  • CVE-2020-37106MedFeb 7, 2026
    risk 0.34cvss 5.3epss 0.00

    Business Live Chat Software 1.0 contains a cross-site request forgery vulnerability that allows attackers to change user account roles without authentication. Attackers can craft a malicious HTML form to modify user privileges by submitting a POST request to the user creation…

  • CVE-2025-40679MedJan 20, 2026
    risk 0.33cvss epss 0.00

    HTML Injection vulnerability in Isshue by Bdtask, consisting os an HTML injection due to a lack os proper validation of user input by sending a POST request to '/category_product_search', affecting the 'product_name' parameter.

  • CVE-2026-10155MedMay 31, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in Bdtask Multi-Store Inventory Management System 1.0. The impacted element is the function accounts_report_search of the file application/modules/accounts/controllers/Accounts.php of the component Accounts Report Handler. Performing a manipulation of…

  • CVE-2021-47769MedJan 15, 2026
    risk 0.31cvss 4.8epss 0.00

    Isshue Shopping Cart 3.5 contains a persistent cross-site scripting vulnerability in title input fields across stock, customer, and invoice modules. Attackers with privileged user accounts can inject malicious scripts that execute on preview, potentially enabling session…

  • CVE-2025-13185MedNov 14, 2025
    risk 0.31cvss 4.7epss 0.00

    A security flaw has been discovered in Bdtask/CodeCanyon News365 up to 7.0.3. This affects an unknown function of the file /admin/dashboard/profile. The manipulation of the argument profile_image/banner_image results in unrestricted upload. The attack can be launched remotely.…

  • CVE-2025-12287MedOct 27, 2025
    risk 0.31cvss 4.7epss 0.00

    A security vulnerability has been detected in Bdtask Wholesale Inventory Control and Inventory Management System up to 20251013. This impacts an unknown function of the file /Admin_dashboard/edit_profile. Such manipulation of the argument first_name/last_name leads to sql…

  • CVE-2020-36012MedJan 27, 2021
    risk 0.31cvss 4.8epss 0.01

    Stored XSS vulnerability in BDTASK Multi-Store Inventory Management System 1.0 allows a local admin to inject arbitrary code via the Customer Name Field.

  • CVE-2026-1600MedJan 29, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The impacted element is an unknown function of the file /hungry/addtocart of the component Add-to-Cart Submission Endpoint. The manipulation of the argument price/allprice…

  • CVE-2026-1599MedJan 29, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The affected element is an unknown function of the file /hungry/placeorder of the component Checkout. Executing a manipulation of the argument…

  • CVE-2025-13239MedNov 16, 2025
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution 5. Affected by this issue is some unknown functionality of the file /submit_checkout. Such manipulation of the argument order_total_amount/cart_total_amount leads…

  • CVE-2025-13179MedNov 14, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 20250320. This issue affects some unknown processing. Such manipulation leads to cross-site request forgery. The attack may be performed from remote. The exploit…