CVE-2024-27476: Leantime

Medium severity, CVSS 4.7. EPSS: 0.6% chance of exploitation in the next 30 days.

Leantime 3.0.6 is vulnerable to HTML Injection via /dashboard/show#/tickets/newTicket.

Affected products

Published 2024-04-10. Last modified 2026-06-17.