---
id: CVE-2021-27695
title: >-
  Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT
  2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via
  any "Add" sections, such as Add Card Building & Floor, or others in the Name
  and Code Par…
summary: >-
  Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT
  2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via
  any "Add" sections, such as Add Card Building & Floor, or others in the Name
  and Code Par…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: openmaint
product: openmaint
affected:
  - openmaint = 2.1-3.3-b
published: '2021-03-15'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-27695'
references:
  - url: 'https://www.exploit-db.com/exploits/49649'
    label: cve@mitre.org
  - url: 'http://openmaint.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.exploit-db.com/exploits/49649'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.03011
epssPercentile: 0.86871
exploitAvailable: true
ingestedAt: '2026-07-05T00:59:25.837Z'
exploits:
  exploitdb: true
  checkedAt: '2026-09-26T09:05:26.435Z'
---

## Overview

Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Floor, or others in the Name and Code Parameters.

## Affected

- `openmaint = 2.1-3.3-b`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
