CVETodo[verified]@CveTodoDisclosure
The text announces a stored XSS flaw in Initiative versions before 0.32.4 that impacts document uploads, with no PoC, exploit, or patch information provided.
CRAC Learning - Tech@cracbotPatch
The post announces CVE‑2026‑28274 with a CVSS score of 8.7, notes that versions before 0.32.4 are vulnerable, and implies that upgrading to 0.32.4 or later provides a patch.
PulsePatch.io@pulsepatchioPatch
A stored XSS vulnerability (CVE-2026-28274) in morelitea/initiative allows token theft via malicious document uploads; users are advised to update Initiative to remediate the issue.
CVE@CVEnewDisclosure
CVE-2026-28274 is a stored XSS vulnerability in Initiative before v0.32.4, with no PoC, exploit, active usage, or patch mentioned.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The text references CVE-2026-28274 as a stored XSS vulnerability in Initiative Project Management Platform (pre‑0.32.4) and provides a link, but offers no further details such as PoC, exploit, or patch information.
CVEFind.com@CveFindComPatch
The post announces a stored XSS vulnerability (CVE‑2026‑28274) in Initiative versions prior to 0.32.4, highlights that attackers could exfiltrate data, and urges users to upgrade to the patched version.
The Hacker Wire@TheHackerWireDisclosure
CVE-2026-28274 is a stored XSS flaw in Initiative’s document upload feature affecting versions before 0.32.4, with no mention of PoC, exploit code, or patch.