CVE-2024-53554: Taigaio Taiga Front

High severity, CVSS 8.0. EPSS: 0.7% chance of exploitation in the next 30 days.

A Client-Side Template Injection (CSTI) vulnerability in the component /project/new/scrum of Taiga v 8.6.1 allows remote attackers to execute arbitrary code by injecting a malicious payload within the new project details.

Affected products

  • Taigaio Taiga Front: before 6.8.1 (fixed in 6.8.1)

Published 2024-11-25. Last modified 2026-06-17.