๐Ÿ” CVE Alert

CVE-2026-53992

MEDIUM 6.1

Reflected XSS in ProjectSend thumbnails-regenerate.php via start_date / end_date Parameters

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

ProjectSend r2029 contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.php that allows remote attackers to inject arbitrary HTML and JavaScript by supplying unsanitized values in the start_date and end_date GET parameters, which are echoed unescaped into HTML attribute values. Attackers can craft a malicious URL that, when followed by an authenticated victim with edit_settings permissions, executes injected scripts in the application origin to steal session cookies or perform unauthorized actions including user management, file management, and application settings changes.

CWE CWE-79
Vendor projectsend
Product projectsend
Published Aug 5, 2026
Last Updated Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for projectsend projectsend

Be the first to know when new medium vulnerabilities affecting projectsend projectsend are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

ProjectSend / ProjectSend
0 โ‰ค b4ad95b

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/projectsend/projectsend github.com: https://github.com/projectsend/projectsend/commit/b4ad95b1bd3d18b23261b7c3496bfbac8ebfe324 vulncheck.com: https://www.vulncheck.com/advisories/reflected-xss-in-projectsend-thumbnails-regenerate-php-via-start-date-end-date-parameters

Credits

Sehwang Kim