CVE-2026-40545
Received Received - Intake
Reflected Cross-Site Scripting in SOPlanning

Publication date: 2026-06-01

Last updated on: 2026-06-01

Assigner: CERT.PL

Description
SOPlanning is vulnerable to Reflected XSS via the taches parameter. An attacker can craft a malicious URL which, when opened by authenticated victim, results in arbitrary JavaScript execution in the victim’s browser. This issue affects SOPlanning version 1.55 and below.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-01
Last Modified
2026-06-01
Generated
2026-06-01
AI Q&A
2026-06-01
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
soplanning soplanning to 1.55 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

The vulnerability in SOPlanning is a Reflected Cross-Site Scripting (XSS) issue that occurs via the 'taches' parameter.

An attacker can create a malicious URL containing harmful JavaScript code. When an authenticated user opens this URL, the malicious script executes in the user's browser.


How can this vulnerability impact me? :

This vulnerability allows attackers to execute arbitrary JavaScript in the context of an authenticated user's browser.

Potential impacts include theft of user session data, unauthorized actions performed on behalf of the user, and exposure to further attacks such as phishing or malware delivery.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart