5.1
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N
Description
SOPlanning is vulnerable to Stored Cross-Site Scripting (XSS) via /process/upload_backup endpoint. An authenticated attacker with access to the backup functionality can upload a crafted ZIP archive containing a malicious user.csv file with embedded JavaScript. The injected code is executed in the victim’s browser when a user clicks the Edit button for the malicious backup.
This issue affects SOPlanning version 1.55 and below.
This issue affects SOPlanning version 1.55 and below.
Basic Information
ID
CVE-2026-40544
Source
CERT-PL
Published
Jun 1, 2026 at 09:03
Affected Product
Vendor
SOPlanning
Product
SOPlanning
Affected Versions
SOPlanning SOPlanning 0