Dated, source-linked records of publicly documented security events affecting popular task and project management products. Each record is visibly classified so a data exposure, API scrape, credential-stuffing attack, supply-chain compromise, and software vulnerability are not presented as interchangeable events.
Research and HIBP index check performed
The short answer
The library covers data exposures at ClickUp and Asana, each scoped to what the companies’ disclosures establish. [1][2]
It separately classifies Trello’s API-scraped profile dataset and monday.com’s downstream impact from the Codecov supply-chain compromise. [3][4]
The remaining records cover credential stuffing against Basecamp accounts and selected exploited vulnerabilities in self-hosted Jira and Confluence. [7][5][6]
Have I Been Pwned coverage is shown separately because absence from HIBP does not mean a vendor has no documented incident. [8]
Documented records.
01
Data exposure
ClickUp’s 2026 feature-flag data exposure.
ClickUp exposed 893 customer emails and one API token through client-readable feature flags in April 2026. See the timeline, scope, response, and sources.
Asana disclosed a 2025 MCP implementation flaw that could expose some customer data across organizations. Source-linked timeline, scope, response, and caveats.
monday.com disclosed read-only source-code access through the 2021 Codecov compromise, with the affected data, response, timeline, and primary sources.
Selected Atlassian Jira & Confluence vulnerability history.
A sourced history of exploited Jira and Confluence Server and Data Center vulnerabilities, including CISA KEV entries and Atlassian security advisories.
Classification describes the mechanism documented by the sources. It is not a severity score, and it
prevents a vulnerability or account attack from being mislabeled as a vendor data breach.
A disclosed software weakness; a vulnerability alone is not evidence of a vendor data breach.
Have I Been Pwned coverage
This table says only whether a product-attributed entry was located in the live HIBP index on July 13, 2026. It does not label any vendor incident-free, and it is intentionally separate from the source-backed records above. [8]
HIBP status only; vulnerabilities and privacy reports require separate classification and evidence.
Wrike
No product-attributed entry located
HIBP status only; this is not a claim of incident-free history.
Airtable
No product-attributed entry located
HIBP status only; this is not a claim of incident-free history.
How these records are built
Every material statement is traced to a named source. The records prioritize vendor statements and advisories, securities filings, regulator publications, Have I Been Pwned records, NVD entries, and CISA’s Known Exploited Vulnerabilities catalog; contemporaneous reporting from established security press supplies details that primary material does not publish. Each page carries inline numbered citations and a dated source list.
Unverified claims do not establish facts and are excluded unless they are material to understanding a documented event and can be attributed precisely to a named source. Any included threat-actor claim remains explicitly labeled as unconfirmed and is never presented as a vendor-confirmed fact. Where a vendor disputes how an incident is labeled, both the dispute and the underlying facts appear.
The Have I Been Pwned table reports HIBP coverage only and was checked against the live breached-sites index on July 13, 2026. Absence of an HIBP entry is not evidence of a clean history: ClickUp, Asana, monday.com, Basecamp, and the Atlassian vulnerability record on this page all demonstrate event classes HIBP does not necessarily represent.
Corrections: if any claim on these pages is inaccurate or has been superseded, email hello@sealtask.com with a source and we will review and correct it.
Hub sources
Primary references for claims made directly on this collection page. Each detailed record carries its own
complete, claim-level source list.
No service is immune to incidents — SealTask included. For a compromise limited to content already
stored by the service, protected workspace content is present as ciphertext. Account metadata, active
sessions, client delivery, and devices remain separate risks. Judge the architecture yourself.