All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-21269
MEDIUMpublished 2026-08-11 17:17 UTC · 1 day ago · modified 2026-08-12 21:03 UTC
4.6
CVSS / 10
// description
is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
// weaknesses (CWE)
- CWE-79