CVE-2026-100898
Published 28 September 2026 · tracked since 28 September 2026
Description
A vulnerability was detected in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/2.0.0-beta1. This affects the function whereRaw of the file app/Filament/Widgets/Timesheet/ActivitiesReport.php of the component Timesheet Dashboard. Performing a manipulation of the argument filter results in sql
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-100894 MEDIUM 6.3
- CVE-2026-100895 MEDIUM 5.3
- CVE-2026-100890 MEDIUM 5.3
- CVE-2026-100891 HIGH 7.3
- CVE-2026-100887 MEDIUM 6.3
- CVE-2026-100888 HIGH 7.3
- CVE-2026-100889 HIGH 7.3
- CVE-2026-100883 MEDIUM 6.3
- CVE-2026-100884 MEDIUM 4.3
- CVE-2026-100885 HIGH 7.3