What is CVE-2026-53992?
CVE-2026-53992: A reflected XSS vulnerability exists in ProjectSend r2029's thumbnails-regenerate.php file. Remote attackers can inject arbitrary HTML and JavaScript by supplying unsanitized values via the start_date and end_date GET parameters, which are echoed unescaped into HTML attributes. It is recommended to update ProjectSend to the latest version immediately.
Azərbaycanca: CVE-2026-53992: ProjectSend r2029-un 'thumbnails-regenerate.php' faylında əks olunan XSS zəifliyi aşkar edilib. Uzaqdan hücum edən şəxs 'start_date' və 'end_date' GET parametrləri vasitəsilə təmizlənməmiş dəyərlər göndərərək ixtiyari HTML/JavaScript kodu yeridə bilər. Təsirə məruz qalmamaq üçün ən qısa zamanda ProjectSend-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
In which ProjectSend file does the CVE-2026-53992 vulnerability exist?
This vulnerability exists in the 'thumbnails-regenerate.php' file of ProjectSend r2029.
How can an attacker inject malicious code using CVE-2026-53992?
A remote attacker can inject arbitrary HTML/JavaScript by supplying unsanitized values via the 'start_date' and 'end_date' GET parameters.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.