CVE-2025-28254 | Leantime up to 3.2.1 processMentions First name cross site scripting (GHSA-95j3-435g-vjcp)
A vulnerability classified as problematic was found in Leantime up to 3.2.1. This vulnerability affects the function processMentions. The manipulation of the argument First name leads to cross site scripting.
This vulnerability was named CVE-2025-28254. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.