PT-2026-96085 · Hyve5 · Leantime

·

CVE-2026-94210

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Hyve5 Leantime versions prior to 3.9.9
Description A flaw in the Kanban Board component allows remote attackers to perform cross-site scripting (XSS), a technique where malicious scripts are injected into trusted websites. The issue resides in the getAllGrouped() function within the app/Domain/Tickets/Services/Tickets.php file.
Recommendations Deploy patch a30a6837b4071ac05a4f58d0e1baa2c62aa8695e for versions prior to 3.9.9.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94210

Affected Products

Leantime