PatchSiren

Taskbuilder CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Taskbuilder CVE published 2026-06-17

CVE-2026-9570

The Taskbuilder WordPress plugin before version 5.0.8 has a Reflected Cross-Site Scripting vulnerability. This issue allows an attacker to inject malicious JavaScript code into a frontend page containing one of its shortcodes, affecting any logged-in user. The vulnerability is caused by the plugin's failure to properly sanitize a URL parameter before echoing it into inline JavaScript. This can lead to a r [truncated]

HIGH Taskbuilder CVE published 2026-06-15

CVE-2026-52697

CVE-2026-52697 is a HIGH-severity vulnerability in the Taskbuilder plugin, affecting versions up to 5.0.7. The issue is a Subscriber SQL Injection vulnerability. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 8.5. The CVE was published on 2026-06-15T21:17:24.377Z and last modified on 2026-06-15T21:24:32.790Z.