Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-19434

Опубликовано: 11 авг. 2026
Источник: nvd
EPSS Низкий

Описание

Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the application origin via HTML markup stored in a finding's severity field, which the frontend interpolates unescaped into class and style attributes when rendering the report.

EPSS

Процентиль: 28%
0.00343
Низкий

Дефекты

CWE-79

Связанные уязвимости

github
около 1 месяца назад

Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the application origin via HTML markup stored in a finding's severity field, which the frontend interpolates unescaped into class and style attributes when rendering the report.

EPSS

Процентиль: 28%
0.00343
Низкий

Дефекты

CWE-79