CVE-2026-28274Disclosure(morelitea / initiative)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch morelitea initiative systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to Stored Cross-Site Scripting (XSS) in the document upload functionality. Any user with upload permissions within the "Initiatives" section can upload a malicious `.html` or `.htm` file as a document. Because the uploaded HTML file is served under the application's origin without proper sandboxing, the embedded JavaScript executes in the context of the application. As a result, authentication tokens, session cookies, or other sensitive data can be exfiltrated to an attacker-controlled server. Additionally, since the uploaded file is hosted under the application's domain, simply sharing the direct file link may result in execution of the malicious script when accessed. Version 0.32.4 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • initiative

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-02-26); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
initiative

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-02-26: 3Mentions · 2026-02-27: 2Mentions · 2026-02-28: 1Mentions · 2026-03-03: 1Patch / Workaround · 2026-02-26: 1Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-03-03: 1Technical Details · 2026-02-26: 3Technical Details · 2026-02-27: 2Technical Details · 2026-02-28: 1Technical Details · 2026-03-03: 102-2602-2702-2803-03
Signal classification3 categories
Disclosure
342.9%
Patch
342.9%
General
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-263
Disclosure2Patch1
2026-02-272
Disclosure1General1
2026-02-281
Patch1
2026-03-031
Patch1
Full discourse7 posts
  • CRAC Learning - Tech@cracbot
    Patch

    CVE-2026-28274 (CVSS:8.7, HIGH) is Analyzed. Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to S..https://nvd.nist.gov/vuln/detail/CVE-2026-28274 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE‑2026‑28274 with a CVSS score of 8.7, notes that versions before 0.32.4 are vulnerable, and implies that upgrading to 0.32.4 or later provides a patch.

    0000033
    173 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    Stored XSS (CVE-2026-28274) in `morelitea/initiative` enables token theft via malicious document uploads. Update `Initiative` to remediate this #XSS #security risk. More info: https://www.pulsepatch.io/posts/cve-2026-28274-morelitea-initiative-token-theft-xss

    Post summary

    A stored XSS vulnerability (CVE-2026-28274) in morelitea/initiative allows token theft via malicious document uploads; users are advised to update Initiative to remediate the issue.

    0000050
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28274 Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to Stored Cross-Site Scripting (XSS) in the docume… https://www.cve.org/CVERecord?id=CVE-2026-28274

    Post summary

    CVE-2026-28274 is a stored XSS vulnerability in Initiative before v0.32.4, with no PoC, exploit, active usage, or patch mentioned.

    00000145
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-28274 Stored Cross-Site Scripting in Initiative Project Management Platform Before 0.32.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28274

    Post summary

    The text references CVE-2026-28274 as a stored XSS vulnerability in Initiative Project Management Platform (pre‑0.32.4) and provides a link, but offers no further details such as PoC, exploit, or patch information.

    0000030
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-28274: HIGH] Alert: Self-hosted platform Initiative has security flaw pre-version 0.32.4 allowing Stored XSS via document upload. Attackers can exfiltrate sensitive data; upgrade to fix.#cve,CVE-2026-28274,#cybersecurity https://cvefind.com/CVE-2026-28274

    Post summary

    The post announces a stored XSS vulnerability (CVE‑2026‑28274) in Initiative versions prior to 0.32.4, highlights that attackers could exfiltrate data, and urges users to upgrade to the patched version.

    0000048
    585 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-28274** pertains to a **Stored Cross-Site Scripting (XSS)** vulnerability in the self-hosted project management platform **Initiative**. This vulnerability exists in versions prior to **0.32.4** and affects the document upload functionality within the "Initiatives" section. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #XSS https://cvetodo.com/cve/CVE-2026-28274

    Post summary

    The text announces a stored XSS flaw in Initiative versions before 0.32.4 that impacts document uploads, with no PoC, exploit, or patch information provided.

    0000039
    20 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-28274 - High Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to Stored Cross-Site Scripting (XSS) in the document upload functionality. ... https://www.thehackerwire.com/vulnerability/CVE-2026-28274/ https://t.co/NZ7dcluO5L

    Post summary

    CVE-2026-28274 is a stored XSS flaw in Initiative’s document upload feature affecting versions before 0.32.4, with no mention of PoC, exploit code, or patch.

    0000041
    115 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmoreliteainitiative---

Explore more