CVE-2024-55416: Thecontrolgroup Voyager
Low severity, CVSS 3.5. EPSS: 20.3% chance of exploitation in the next 30 days.
DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can be executed.
Affected products
- Thecontrolgroup Voyager: up to and including 1.8.0
Published 2025-01-30. Last modified 2026-06-17.