5.1
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Description
SOPlanning is vulnerable to Reflected XSS via the taches parameter. An attacker can craft a malicious URL which, when opened by authenticated victim, results in arbitrary JavaScript execution in the victimβs browser.
This issue affects SOPlanning version 1.55 and below.
This issue affects SOPlanning version 1.55 and below.
Basic Information
ID
CVE-2026-40545
Source
CERT-PL
Published
Jun 1, 2026 at 09:03
Affected Product
Vendor
SOPlanning
Product
SOPlanning
Affected Versions
SOPlanning SOPlanning 0