CVE-2026-41250

MEDIUM

XSS in taiga-front

Title source: cna
STIX 2.1

Description

Taiga is a project management platform for startups and agile developers. Prior 6.9.1, Taiga front is vulnerable to stored XSS. This vulnerability is fixed in 6.9.1.

Scores

CVSS v3 5.7
EPSS 0.0028
EPSS Percentile 19.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
taigaio/taiga-front < 6.9.1
Published May 11, 2026
Tracked Since May 11, 2026