๐Ÿ” CVE Alert

CVE-2026-28274

HIGH 8.7

Initiative Vulnerable to Token Theft via Stored XSS in Document Uploads

CVSS Score
8.7
EPSS Score
0.0%
EPSS Percentile
0th

Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to Stored Cross-Site Scripting (XSS) in the document upload functionality. Any user with upload permissions within the "Initiatives" section can upload a malicious `.html` or `.htm` file as a document. Because the uploaded HTML file is served under the application's origin without proper sandboxing, the embedded JavaScript executes in the context of the application. As a result, authentication tokens, session cookies, or other sensitive data can be exfiltrated to an attacker-controlled server. Additionally, since the uploaded file is hosted under the application's domain, simply sharing the direct file link may result in execution of the malicious script when accessed. Version 0.32.4 fixes the issue.

CWE CWE-79 CWE-434
Vendor morelitea
Product initiative
Published Feb 26, 2026
Last Updated Feb 27, 2026
Stay Ahead of the Next One

Get instant alerts for morelitea initiative

Be the first to know when new high vulnerabilities affecting morelitea initiative are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

Morelitea / initiative
< 0.32.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Morelitea/initiative/security/advisories/GHSA-v38c-x27x-p584 github.com: https://github.com/Morelitea/initiative/releases/tag/v0.32.4