SquaredUp allowed Stored XSS before version 4.6.0. A user was able to create a dashboard that executed malicious content in iframe or by uploading an SVG that contained a script.
https://support.squaredup.com/hc/en-us/articles/360019427258-CVE-2020-9390-Stored-cross-site-scripting
https://support.squaredup.com/hc/en-us/articles/360017568258
https://scomsupport.squaredup.com/hc/en-us/articles/8862922003869-CVE-2020-9390-Stored-cross-site-scripting-Web-Content-and-Visio-tile-
Source: Mitre, NVD
Published: 2021-02-03
Updated: 2026-06-17
Base Score: 3.5
Vector: CVSS2#AV:N/AC:M/Au:S/C:N/I:P/A:N
Severity: Low
Base Score: 5.4
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Severity: Medium
EPSS: 0.00445