CVE-2024-53554: Taigaio Taiga Front
High severity, CVSS 8.0. EPSS: 0.7% chance of exploitation in the next 30 days.
A Client-Side Template Injection (CSTI) vulnerability in the component /project/new/scrum of Taiga v 8.6.1 allows remote attackers to execute arbitrary code by injecting a malicious payload within the new project details.
Affected products
- Taigaio Taiga Front: before 6.8.1 (fixed in 6.8.1)
Published 2024-11-25. Last modified 2026-06-17.