216.73.217.22

CVE-2026-40544

· Published 01/06/2026 09:16 · Modified 01/06/2026 16:37

Labels: CVE-2026-40544 2026-06-01CVE-2026-40544CWE-79[email protected]

Essential information

Published
01/06/2026 09:16
Modified
01/06/2026 16:37
Author
Creator
CVSS
5.1 MEDIUM (v3) 5.1 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

SOPlanning is vulnerable to Stored Cross-Site Scripting (XSS) via /process/upload_backup endpoint. An authenticated attacker with access to the backup functionality can upload a crafted ZIP archive containing a malicious user.csv file with embedded JavaScript. The injected code is executed in the victim’s browser when a user clicks the Edit button for the malicious backup. This issue affects SOPlanning version 1.55 and below.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
soplanning / soplanning cpe:2.3:a:soplanning:soplanning:<=1.55:*:*:*:*:*:*:*
soplanning / soplanning cpe:2.3:a:soplanning:soplanning:*:*:*:*:*:*:*:*

References