PT-2026-22222 · Unknown · Initiative

G3Xar

·

Published

2026-02-26

·

Updated

2026-03-03

·

CVE-2026-28274

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Initiative versions prior to 0.32.4
Description Initiative is a self-hosted project management platform vulnerable to Stored Cross-Site Scripting (XSS) in the document upload functionality. Users with upload permissions within the "Initiatives" section can upload malicious .html or .htm files. These files are served under the application’s origin without proper sandboxing, allowing embedded JavaScript to execute in the application’s context. This can lead to the exfiltration of authentication tokens, session cookies, or other sensitive data to an attacker-controlled server. Sharing the direct file link may also result in the execution of the malicious script when accessed.
Recommendations Upgrade to version 0.32.4 or later.

Exploit

Fix

Unrestricted File Upload

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28274
GHSA-V38C-X27X-P584

Affected Products

Initiative