CVE-2024-55416: Thecontrolgroup Voyager

Low severity, CVSS 3.5. EPSS: 20.3% chance of exploitation in the next 30 days.

DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can be executed.

Affected products

Published 2025-01-30. Last modified 2026-06-17.