PatchSiren

DevaslanPHP CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW DevaslanPHP CVE published 2026-09-28

CVE-2026-100900

A server-side request forgery vulnerability was found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1 in the Jira Import component. The vulnerability is due to the manipulation of the argument host/username/token in the file /jira-import, which leads to server-side request forgery. The attack can be initiated remotely. Defenders should prioritize verifying affected versions and asse [truncated]

LOW DevaslanPHP CVE published 2026-09-28

CVE-2026-100899

A SQL injection vulnerability exists in DevaslanPHP project-management versions 1.2.1 through 1.2.4 and v2.0.0-beta1. The flaw is located in the Timesheet Dashboard, specifically in the MonthlyReport.php file. An attacker can manipulate the filter argument to execute SQL injection attacks remotely. This vulnerability allows remote attackers to execute malicious SQL queries, potentially leading to data tam [truncated]

LOW DevaslanPHP CVE published 2026-09-28

CVE-2026-100898

A SQL injection vulnerability was detected in DevaslanPHP project-management versions 1.2.1 through 2.0.0-beta1. This affects the function whereRaw of the file app/Filament/Widgets/Timesheet/ActivitiesReport.php in the Timesheet Dashboard component. The attack can be carried out remotely by manipulating the filter argument. Defenders should verify exposure, assess deployment context, and consider mitigati [truncated]