7.3
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Description
OnboardLite is a comprehensive membership lifecycle platform built for student organizations at the University of Central Florida. Versions of the software prior to commit 1d32081a66f21bcf41df1ecb672490b13f6e429f have a stored cross-site scripting vulnerability that can be rendered to an admin when they attempt to migrate a user's discord account in the dashboard. Commit 1d32081a66f21bcf41df1ecb672490b13f6e429f patches the issue.
Basic Information
ID
CVE-2026-23880
Source
GitHub_M
Published
Jan 19, 2026 at 20:55
Affected Product
Vendor
HackUCF
Product
OnboardLite
Version
< 1d32081a66f21bcf41df1ecb672490b13f6e429f
Affected Versions
HackUCF OnboardLite < 1d32081a66f21bcf41df1ecb672490b13f6e429f