CVE-2024-27705: Leantime

High severity, CVSS 7.6. EPSS: 0.6% chance of exploitation in the next 30 days.

Cross Site Scripting vulnerability in Leantime v3.0.6 allows attackers to execute arbitrary code via upload of crafted PDF file to the files/browse endpoint.

Affected products

Published 2024-04-03. Last modified 2026-06-17.