SOPlanning is vulnerable to Stored XSS in /status endpoint. Malicious attacker with an account can inject arbitrary HTML and JS into website, which will be rendered/executed when opening multiple pages.
This issue was fixed in version 1.55.
[ { "events": [ { "introduced": "0" }, { "fixed": "1.55.00" } ] } ]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62729.json"