CVE-2026-94210 | Hyve5 Leantime up to 3.9.8 Kanban Board Tickets.php getAllGrouped cross site scripting

SecurityVulns

A vulnerability identified as problematic has been detected in Hyve5 Leantime up to 3.9.8. Affected by this vulnerability is the function getAllGrouped of the file app/Domain/Tickets/Services/Tickets.php of the component Kanban Board. This manipulation causes cross site scripting.

This vulnerability is tracked as CVE-2026-94210. The attack is possible to be carried out remotely. Moreover, an exploit is present.

To fix this issue, it is recommended to deploy a patch.VulDB Recent EntriesRead More