Hyve5 · Leantime · CVE-2026-94210
**Name of the Vulnerable Software and Affected Versions**
Hyve5 Leantime versions prior to 3.9.9
**Description**
A flaw in the Kanban Board component allows remote attackers to perform cross-site scripting (XSS), a technique where malicious scripts are injected into trusted websites. The issue resides in the `getAllGrouped()` function within the `app/Domain/Tickets/Services/Tickets.php` file.
**Recommendations**
Deploy patch a30a6837b4071ac05a4f58d0e1baa2c62aa8695e for versions prior to 3.9.9.