CVE-2026-28274 - Initiative Vulnerable to Token Theft via Stored XSS in Document Uploads

CVE-2026-28274 - Initiative Vulnerable to Token Theft via Stored XSS in Document Uploads

CVE ID : CVE-2026-28274 Published : Feb. 26, 2026, 11:16 p.m. | 53 minutes ago Description : Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to Stored Cross-Site Scripting (XSS) in the document upload functionality. Any user with upload permissions within the

CVE Details

Published
Feb. 26, 2026
Impact: XSS