VYPR

Taiga

by Taigaio

Source repositories

CVEs (5)

  • CVE-2024-53555HigNov 26, 2024
    risk 0.57cvss 8.8epss 0.01

    A CSV injection vulnerability in Taiga v6.8.1 allows attackers to execute arbitrary code via uploading a crafted CSV file.

  • CVE-2024-53554HigNov 25, 2024
    risk 0.52cvss 8.0epss 0.01

    A Client-Side Template Injection (CSTI) vulnerability in the component /project/new/scrum of Taiga v 8.6.1 allows remote attackers to execute arbitrary code by injecting a malicious payload within the new project details.

  • CVE-2024-53556MedNov 25, 2024
    risk 0.40cvss 6.1epss 0.00

    An Open Redirect vulnerability in Taiga v6.8.1 allows attackers to redirect users to arbitrary websites via appending a crafted link to /login?next= in the login page URL.

  • CVE-2026-41250MedMay 11, 2026
    risk 0.30cvss 5.7epss 0.00

    Taiga is a project management platform for startups and agile developers. Prior 6.9.1, Taiga front is vulnerable to stored XSS. This vulnerability is fixed in 6.9.1.

  • CVE-2026-59097MedJul 2, 2026
    risk 0.00cvss 5.3epss 0.01

    Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to create default due-date records in any project by exploiting unprotected POST endpoints on the user-story, task, and issue due-date API viewsets. Attackers can…