← Back

Rukovoditel

rukovoditel

52 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Rukovoditel
rukovoditel

CVEs (52)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rukovoditel
1Rukovoditel
Jun 17, 2026
Dec 17, 2025
6.2 MEDIUM· v4
8.8 HIGH· v3
N/A· v2
Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field. Attackers can craft payloads like =calc|a!z| to trigger code execution when...Show more
Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field. Attackers can craft payloads like =calc|a!z| to trigger code execution when an admin exports customer data as a CSV file.Show less
1Rukovoditel
1Rukovoditel
Jun 17, 2026
Dec 16, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert iframe and script payloads in application copyright text to ex...Show more
Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert iframe and script payloads in application copyright text to execute arbitrary JavaScript in victim browsers.Show less
1Rukovoditel
1Rukovoditel
Jun 17, 2026
Dec 16, 2025
5.1 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert XSS payloads in project task comments to execute arbitr...Show more
Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert XSS payloads in project task comments to execute arbitrary JavaScript in victim browsers.Show less
1Rukovoditel
1Rukovoditel
Jun 17, 2026
May 4, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save.
1Rukovoditel
1Rukovoditel
Jun 17, 2026
May 4, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Rukovoditel before 3.5.3 allows XSS via user_photo to My Page.
1Rukovoditel
1Rukovoditel
Jun 17, 2026
Jan 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request.
1Rukovoditel
1Rukovoditel
Jun 17, 2026
Dec 5, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Rukovoditel v3.2.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in the component /rukovoditel/index.php?module=users/login. This vulnerability allows attackers to cause a Denial of Servi...Show more
Rukovoditel v3.2.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in the component /rukovoditel/index.php?module=users/login. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.Show less
1Rukovoditel
1Rukovoditel
Jul 9, 2026
Dec 2, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in /index.php?module=configuration/application. This vulnerability allows attackers to execute arbitrary web scripts or HTML...Show more
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in /index.php?module=configuration/application. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Copyright Text field after clicking "Add".Show less
1Rukovoditel
1Rukovoditel
Jul 9, 2026
Dec 2, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Form tab function at /index.php?module=entities/forms&entities_id=24. This vulnerability allows attackers to e...Show more
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Form tab function at /index.php?module=entities/forms&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.Show less
1Rukovoditel
1Rukovoditel
Jul 9, 2026
Dec 2, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to exe...Show more
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.Show less
1Rukovoditel
1Rukovoditel
Jul 9, 2026
Dec 2, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to exe...Show more
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Short Name field.Show less
1Rukovoditel
1Rukovoditel
Jul 9, 2026
Dec 2, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group feature at/index.php?module=entities/entities_groups. This vulnerability allows attackers to execute ar...Show more
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group feature at/index.php?module=entities/entities_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field after clicking "Add".Show less
1Rukovoditel
1Rukovoditel
Jul 9, 2026
Dec 2, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Highlight Row feature at /index.php?module=entities/listing_types&entities_id=24. This vulnerability allows attackers...Show more
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Highlight Row feature at /index.php?module=entities/listing_types&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Note field after clicking "Add".Show less
1Rukovoditel
1Rukovoditel
Jul 9, 2026
Dec 2, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Page function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute...Show more
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Page function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.Show less
1Rukovoditel
1Rukovoditel
Jul 9, 2026
Dec 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter.
1Rukovoditel
1Rukovoditel
Jul 9, 2026
Dec 2, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Announcement function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to...Show more
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Announcement function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.Show less
1Rukovoditel
1Rukovoditel
Jun 17, 2026
Nov 14, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the order_by parameter at /rukovoditel/index.php?module=logs/view&type=php.
1Rukovoditel
1Rukovoditel
Jun 17, 2026
Oct 28, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_configure/index) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts...Show more
A stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_configure/index) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter after clicking "Add info block".Show less
1Rukovoditel
1Rukovoditel
Jun 17, 2026
Oct 28, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in the Users Access Groups feature (/index.php?module=users_groups/users_groups) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or...Show more
A stored cross-site scripting (XSS) vulnerability in the Users Access Groups feature (/index.php?module=users_groups/users_groups) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add New Group".Show less
1Rukovoditel
1Rukovoditel
Jun 17, 2026
Oct 28, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the reports_id parameter.