Stored XSS in SOPlanning
Vulnerability Description
SOPlanning is vulnerable to Stored XSS in /taches endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when opening editor. This issue was fixed in version 1.55.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-62296
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Łukasz Jaworski (Pentest Limited)
More from SOPlanning
View All →Affected Vendor
SOPlanning
View all reports →