CVE-2026-94210

medium

Description

A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this vulnerability is the function getAllGrouped of the file app/Domain/Tickets/Services/Tickets.php of the component Kanban Board. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: a30a6837b4071ac05a4f58d0e1baa2c62aa8695e. To fix this issue, it is recommended to deploy a patch.

References

https://vuldb.com/vuln/408068/cti

https://vuldb.com/vuln/408068

https://vuldb.com/submit/894646

https://vuldb.com/cve/CVE-2026-94210

https://github.com/natanmorette-thoropass/thoropass-vuln-research-program/tree/main/2026/Stored%20XSS%20in%20Leantime%20Kanban%20Swimlane%20Headers%20Enables%20Privilege%20Escalation%20to%20Owner

https://github.com/Leantime/leantime/pull/3767

https://github.com/Leantime/leantime/commit/a30a6837b4071ac05a4f58d0e1baa2c62aa8695e

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-83890

Details

Source: Mitre, NVD

Published: 2026-09-21

Updated: 2026-09-21

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 3.5

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

Severity: Low

CVSS v4

Base Score: 5.1

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00356