TaskFreak is affected by XSS vulnerabilites on specified version 0.6.4;
index.php (dir, show, sort, sContext) XSS
index.php (sContext) - Stored XSS
Disclosure Timeline:
23/01/2011 - First contact
30/01/2011 - Sent the vulnerability details
16/08/2012 - Second contact - No reply
19/10/2012 - Advisory released