Reflected Cross-Site Scripting in ProjectSend by ProjectSend
CVE-2026-53992
5.1MEDIUM
What is CVE-2026-53992?
ProjectSend r2029 is vulnerable to a reflected cross-site scripting (XSS) issue in the thumbnails-regenerate.php file. Remote attackers can exploit this vulnerability by providing unsanitized values to the start_date and end_date GET parameters. These values are echoed unescaped into HTML attribute values, enabling attackers to craft a malicious URL. When accessed by an authenticated user with edit_settings permissions, this can lead to the execution of injected scripts within the application context. As a result, attackers can potentially steal session cookies, perform unauthorized actions affecting user management, file management, and alter application settings.
Affected Version(s)
ProjectSend 0
