Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Alvinovando-Thoropass

#41011of 57,349
7.3Total CVSS
Vulnerabilities · 2
Low
1
Medium
1
PT-2026-96085
4.0
2026-09-21
Hyve5 · Leantime · CVE-2026-94210
**Name of the Vulnerable Software and Affected Versions** Hyve5 Leantime versions prior to 3.9.9 **Description** A flaw in the Kanban Board component allows remote attackers to perform cross-site scripting (XSS), a technique where malicious scripts are injected into trusted websites. The issue resides in the `getAllGrouped()` function within the `app/Domain/Tickets/Services/Tickets.php` file. **Recommendations** Deploy patch a30a6837b4071ac05a4f58d0e1baa2c62aa8695e for versions prior to 3.9.9.
PT-2026-96088
3.3
2026-09-21
Hyve5 · Leantime · CVE-2026-94211
**Name of the Vulnerable Software and Affected Versions** Hyve5 Leantime versions prior to 3.9.9 **Description** A remote cross-site scripting issue exists in the Project Dashboard component within the file `/app/Domain/Dashboard/Templates/show.blade.php`. An attacker with EDIT permissions can inject a malicious payload into a label name, which is then echoed raw to any user viewing the project dashboard. **Recommendations** Update Hyve5 Leantime to version 3.9.9 or later.