AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T16:16:57.920Z and has not been modified since then. The ProjectSend r2029 version contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.php. The vulnerability allows remote attackers to inject arbitrary HTML and JavaScript by supplying unsanitized values in the start_da [truncated]
A security flaw has been discovered in ProjectSend r2002, affecting the file upload.php, leading to cross-site request forgery. The attack may be initiated remotely and has been publicly disclosed. Upgrading to version r2029 resolves this issue. This vulnerability has a CVSS score of 2.1 and is considered Low severity. Users should be aware and take steps to upgrade.
Known exploitedProjectSendCVE published 2024-12-03
CVE-2024-11680 is a ProjectSend improper authentication vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2024-12-03. Because it is listed as known exploited, affected environments should prioritize the official vendor and government guidance, verify whether their deployed version is fixed or mitigated, and discontinue use if no effective mitigation is available.