SOPlanning is vulnerable to Stored XSS in /taches endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when opening editor.
This issue was fixed in version 1.55.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62296.json"
[ { "events": [ { "introduced": "0" }, { "fixed": "1.55.00" } ] } ]