VYPR

Holded

by Holded

CVEs (2)

  • CVE-2025-1076MedFeb 6, 2025
    risk 0.31cvss 4.8epss 0.00

    A Stored Cross-Site Scripting (Stored XSS) vulnerability has been found in the Holded application. This vulnerability could allow an attacker to store a JavaScript payload within the editable ‘name’ and ‘icon’ parameters of the Activities functionality.

  • CVE-2024-4026MedApr 22, 2024
    risk 0.30cvss 4.6epss 0.00

    Cross-Site Scripting (XSS) vulnerability in the Holded application. This vulnerability could allow an attacker to store a JavaScript payload within all editable parameters within the 'General' and 'Team ID' functionalities, which could result in a session takeover.