
CVE-2026-41467 ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the file upload functionality where the checkValidFileName() function fai… https://www.cve.org/CVERecord?id=CVE-2026-41467
Post summary
The text discloses that ProjeQtor versions 7.0–12.4.3 are vulnerable to stored XSS via file upload because of an ineffective filename validation function.

