Cross-site Scripting Vulnerability in Emilia Projects Progress Planner
CVE-2026-28116
5.9MEDIUM
What is CVE-2026-28116?
The Progress Planner plugin by Emilia Projects is vulnerable to a Cross-site Scripting (XSS) attack due to improper neutralization of input during web page generation. This vulnerability allows attackers to inject malicious scripts into web pages viewed by users. When executed, these scripts can compromise user data, potentially leading to unauthorized access and data breaches. The vulnerability impacts all versions from n/a through 1.9.0, making it critical for users to apply patches or updates to mitigate risk.
Affected Version(s)
Progress Planner <= 1.9.0