CVE-2026-29828

DooTask v1.6.27 has a Cross-Site Scripting (XSS) vulnerability in the /manage/project/<id> page via the input field projectDesc.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dootask:dootask:*:*:*:*:*:*:*:*

History

02 Apr 2026, 20:12

Type Values Removed Values Added
First Time Dootask
Dootask dootask
Summary
  • (es) DooTask v1.6.27 tiene una vulnerabilidad de cross-site scripting (XSS) en la página /manage/project/ a través del campo de entrada projectDesc.
CPE cpe:2.3:a:dootask:dootask:*:*:*:*:*:*:*:*
References () https://github.com/J4cky1028/vulnerability-research/tree/main/CVE-2026-29828 - () https://github.com/J4cky1028/vulnerability-research/tree/main/CVE-2026-29828 - Third Party Advisory
References () https://github.com/kuaifan/dootask - () https://github.com/kuaifan/dootask - Product

23 Mar 2026, 15:16

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

20 Mar 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 17:16

Updated : 2026-04-02 20:12


NVD link : CVE-2026-29828

Mitre link : CVE-2026-29828

CVE.ORG link : CVE-2026-29828


JSON object : View

Products Affected

dootask

  • dootask
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')