PT-2026-39658 · Taiga · Taiga
Robert-Fl
·
Published
2026-05-11
·
Updated
2026-05-13
·
CVE-2026-41250
CVSS v3.1
5.7
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Taiga versions prior to 6.9.1
Description
Taiga, a project management platform for startups and agile developers, contains a stored Cross-Site Scripting (XSS) issue in its front-end. Stored XSS occurs when an application receives data from a user and includes that data within its later HTTP responses in a way that allows an attacker to execute scripts in the victim's browser.
Recommendations
Update to version 6.9.1.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Taiga