Common Weakness Enumeration

CWE-79

Allowed

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Abstraction: Base · Status: Stable

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

71214 vulnerabilities reference this CWE, most recent first.

CVE-2026-95957 (GCVE-0-2026-95957)

Vulnerability from cvelistv5 – Published: 2026-09-23 02:30 – Updated: 2026-09-23 14:33 X_Freeware
VLAI
Title
SourceCodester Smart Attendance System with QR Code Scanner Self-Registration student_signup.php prepend cross site scripting
Summary
A vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0. This issue affects the function prepend of the file student_signup.php of the component Self-Registration. Performing a manipulation of the argument full_name results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
SSVC
Exploitation: poc Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-23 14:30 UTC
CWE
References
Impacted products
Vendor Product Version
SourceCodester Smart Attendance System with QR Code Scanner Affected: 1.0
    cpe:2.3:a:sourcecodester:smart_attendance_system_with_qr_code_scanner:*:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-95957",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-23T14:30:15.111107Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-23T14:33:43.965Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:sourcecodester:smart_attendance_system_with_qr_code_scanner:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "Self-Registration"
          ],
          "product": "Smart Attendance System with QR Code Scanner",
          "vendor": "SourceCodester",
          "versions": [
            {
              "status": "affected",
              "version": "1.0"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "jinxing (VulDB User)"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0. This issue affects the function prepend of the file student_signup.php of the component Self-Registration. Performing a manipulation of the argument full_name results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public and could be used."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
            "version": "4.0"
          }
        },
        {
          "cvssV3_1": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 5,
            "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-79",
              "description": "Cross Site Scripting",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-94",
              "description": "Code Injection",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-23T02:30:16.093Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "name": "VDB-408556 | SourceCodester Smart Attendance System with QR Code Scanner Self-Registration student_signup.php prepend cross site scripting",
          "tags": [
            "vdb-entry",
            "technical-description"
          ],
          "url": "https://vuldb.com/vuln/408556"
        },
        {
          "name": "VDB-408556 | CTI Indicators (IOB, IOC, TTP, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/vuln/408556/cti"
        },
        {
          "name": "CVE-2026-95957 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/cve/CVE-2026-95957"
        },
        {
          "name": "Submit #953379 | SourceCodester Smart Attendance System with QR Code Scanner 1.0 Cross Site Scripting (CWE-79)",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/submit/953379"
        },
        {
          "tags": [
            "exploit"
          ],
          "url": "https://github.com/Jack-MRJ/Smart-Attendance-System-with-QR-Code-Scanner"
        },
        {
          "tags": [
            "product"
          ],
          "url": "https://www.sourcecodester.com/"
        }
      ],
      "tags": [
        "x_freeware"
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-22T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2026-09-22T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2026-09-22T19:31:26.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "SourceCodester Smart Attendance System with QR Code Scanner Self-Registration student_signup.php prepend cross site scripting",
      "x_generator": [
        "VulDB PVTS v202609"
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2026-95957",
    "datePublished": "2026-09-23T02:30:16.093Z",
    "dateReserved": "2026-09-22T17:26:21.270Z",
    "dateUpdated": "2026-09-23T14:33:43.965Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-95866 (GCVE-0-2026-95866)

Vulnerability from cvelistv5 – Published: 2026-09-25 07:40 – Updated: 2026-09-25 13:00
VLAI
Title
User Profile Builder <= 4.0.2 - Unauthenticated Stored Cross-Site Scripting via Avatar Field
Summary
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The zero-length multipart file branch in wppb_save_avatar_value() writes the raw request value directly to user meta, bypassing the wppb_save_attachment_id()/wppb_verify_attachment_id() validation path; the stored payload is later adopted as a WordPress attachment URL and rendered unescaped by wppb_default_fields_make_upload_button() when an administrator views the affected account.
SSVC
Exploitation: none Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-25 12:50 UTC
CWE
  • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-95866",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-25T12:50:45.923425Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-25T13:00:15.061Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles \u0026 User Role Editor",
          "vendor": "cozmoslabs",
          "versions": [
            {
              "lessThanOrEqual": "4.0.2",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Jonah Burgess (CryptoCat)"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "The User Profile Builder \u2013 Beautiful User Registration Forms, User Profiles \u0026 User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The zero-length multipart file branch in wppb_save_avatar_value() writes the raw request value directly to user meta, bypassing the wppb_save_attachment_id()/wppb_verify_attachment_id() validation path; the stored payload is later adopted as a WordPress attachment URL and rendered unescaped by wppb_default_fields_make_upload_button() when an administrator views the affected account."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-79",
              "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-25T07:40:27.394Z",
        "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "shortName": "Wordfence"
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/68cef86f-3a6a-47c4-a092-de3bb40ac157?source=cve"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/profile-builder/tags/4.0.2/front-end/default-fields/upload/upload_helper_functions.php#L286"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/profile-builder/tags/4.0.2/front-end/default-fields/avatar/avatar.php#L127"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/profile-builder/tags/4.0.2/front-end/default-fields/avatar/avatar.php#L67"
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3708665%40profile-builder\u0026new=3708665%40profile-builder"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-22T17:15:13.000Z",
          "value": "Vendor Notified"
        },
        {
          "lang": "en",
          "time": "2026-09-24T18:54:29.000Z",
          "value": "Disclosed"
        }
      ],
      "title": "User Profile Builder \u003c= 4.0.2 - Unauthenticated Stored Cross-Site Scripting via Avatar Field"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
    "assignerShortName": "Wordfence",
    "cveId": "CVE-2026-95866",
    "datePublished": "2026-09-25T07:40:27.394Z",
    "dateReserved": "2026-09-22T17:00:07.795Z",
    "dateUpdated": "2026-09-25T13:00:15.061Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-95864 (GCVE-0-2026-95864)

Vulnerability from cvelistv5 – Published: 2026-09-25 07:40 – Updated: 2026-09-25 13:00
VLAI
Title
Themify Builder <= 7.8.1 - Unauthenticated Stored Cross-Site Scripting via 'css[fonts]' Parameter
Summary
The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'css[fonts]' Parameter in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce required to reach the vulnerable endpoint is embedded in plain sight within the front-end page markup for all visitors, reducing the access control to a CSRF token rather than an authentication barrier and making the endpoint fully exploitable by unauthenticated attackers.
SSVC
Exploitation: none Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-25 12:49 UTC
CWE
  • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Impacted products
Vendor Product Version
themifyme Themify Builder Affected: 0 , ≤ 7.8.1 (semver)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-95864",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-25T12:49:15.738448Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-25T13:00:13.641Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Themify Builder",
          "vendor": "themifyme",
          "versions": [
            {
              "lessThanOrEqual": "7.8.1",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "thevietronin"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via \u0027css[fonts]\u0027 Parameter in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce required to reach the vulnerable endpoint is embedded in plain sight within the front-end page markup for all visitors, reducing the access control to a CSRF token rather than an authentication barrier and making the endpoint fully exploitable by unauthenticated attackers."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-79",
              "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-25T07:40:31.136Z",
        "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "shortName": "Wordfence"
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fc021ee6-694a-426b-b399-8dd015fd99d2?source=cve"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.8.1/themify/class-themify-enqueue.php#L1757"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.8.1/classes/class-themify-builder-stylesheet.php#L160"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.8.1/classes/class-themify-builder-stylesheet.php#L317"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.8.1/classes/class-themify-builder-stylesheet.php#L514"
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3710320%40themify-builder\u0026new=3710320%40themify-builder"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-22T17:13:24.000Z",
          "value": "Vendor Notified"
        },
        {
          "lang": "en",
          "time": "2026-09-24T19:02:16.000Z",
          "value": "Disclosed"
        }
      ],
      "title": "Themify Builder \u003c= 7.8.1 - Unauthenticated Stored Cross-Site Scripting via \u0027css[fonts]\u0027 Parameter"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
    "assignerShortName": "Wordfence",
    "cveId": "CVE-2026-95864",
    "datePublished": "2026-09-25T07:40:31.136Z",
    "dateReserved": "2026-09-22T16:58:20.070Z",
    "dateUpdated": "2026-09-25T13:00:13.641Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-95817 (GCVE-0-2026-95817)

Vulnerability from cvelistv5 – Published: 2026-10-02 07:39 – Updated: 2026-10-02 18:01
VLAI
Title
DoFollow Case by Case <= 3.6.0 - Unauthenticated Stored Cross-Site Scripting via Comment Content
Summary
The DoFollow Case by Case plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Comment moderation delays but does not prevent exploitation — once an administrator approves the visually innocuous comment, the stored payload executes in the browser of every subsequent visitor to the affected post.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-02 18:01 UTC
CWE
  • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Impacted products
Vendor Product Version
apasionados DoFollow Case by Case Affected: 0 , ≤ 3.6.0 (semver)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-95817",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-02T18:01:12.279233Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-02T18:01:27.679Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "DoFollow Case by Case",
          "vendor": "apasionados",
          "versions": [
            {
              "lessThanOrEqual": "3.6.0",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "theviper17y"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "The DoFollow Case by Case plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Comment moderation delays but does not prevent exploitation \u2014 once an administrator approves the visually innocuous comment, the stored payload executes in the browser of every subsequent visitor to the affected post."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-79",
              "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-02T07:39:22.487Z",
        "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "shortName": "Wordfence"
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2e426151-a8cb-48b9-9fa4-170fc3371629?source=cve"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/dofollow-case-by-case/tags/3.6.0/dofollow-case-by-case.php#L733"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/dofollow-case-by-case/tags/3.6.0/dofollow-case-by-case.php#L797"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/dofollow-case-by-case/tags/3.6.0/dofollow-case-by-case.php#L748"
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3721278%40dofollow-case-by-case\u0026new=3721278%40dofollow-case-by-case"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-29T02:40:29.000Z",
          "value": "Vendor Notified"
        },
        {
          "lang": "en",
          "time": "2026-10-01T18:52:42.000Z",
          "value": "Disclosed"
        }
      ],
      "title": "DoFollow Case by Case \u003c= 3.6.0 - Unauthenticated Stored Cross-Site Scripting via Comment Content"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
    "assignerShortName": "Wordfence",
    "cveId": "CVE-2026-95817",
    "datePublished": "2026-10-02T07:39:22.487Z",
    "dateReserved": "2026-09-22T15:51:14.511Z",
    "dateUpdated": "2026-10-02T18:01:27.679Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-95812 (GCVE-0-2026-95812)

Vulnerability from cvelistv5 – Published: 2026-09-22 20:21 – Updated: 2026-10-06 13:37
VLAI
Title
ClipBucket v5 before 5.5.3-#182 Reflected XSS via Query Parameters
Summary
ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the sort_link() helper function that fails to sanitize cat, sort, and time query parameters. Attackers can craft malicious requests with injected script payloads in these parameters to execute arbitrary JavaScript in victims' browsers under the application origin.
SSVC
Exploitation: poc Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-23 15:39 UTC
CWE
  • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Impacted products
Vendor Product Version
MacWarrior clipbucket-v5 Affected: 0 , < 5.5.3-#182 (custom)
Unaffected: 5.5.3-#182 (custom)
    cpe:2.3:a:clip-bucket:clipbucket:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-08-19 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-95812",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-23T15:39:05.323788Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-23T15:39:12.904Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "collectionURL": "https://github.com/MacWarrior/clipbucket-v5",
          "defaultStatus": "unaffected",
          "packageURL": "pkg:github/MacWarrior/clipbucket-v5",
          "product": "clipbucket-v5",
          "repo": "https://github.com/MacWarrior/clipbucket-v5",
          "vendor": "MacWarrior",
          "versions": [
            {
              "lessThan": "5.5.3-#182",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "5.5.3-#182",
              "versionType": "custom"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:clip-bucket:clipbucket:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.5.3-#182",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "leediay153 from Viettel Post"
        }
      ],
      "datePublic": "2026-08-19T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the sort_link() helper function that fails to sanitize cat, sort, and time query parameters. Attackers can craft malicious requests with injected script payloads in these parameters to execute arbitrary JavaScript in victims\u0027 browsers under the application origin."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "NONE",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "LOW",
            "subIntegrityImpact": "LOW",
            "userInteraction": "PASSIVE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-79",
              "description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-06T13:37:06.270Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "Patch Commit",
          "tags": [
            "patch"
          ],
          "url": "https://github.com/MacWarrior/clipbucket-v5/commit/032f46937e091e22afa6c99f2c888575cc94e44b"
        },
        {
          "name": "clipbucket-v5 5.5.3-%23182 Release Notes",
          "tags": [
            "release-notes"
          ],
          "url": "https://github.com/MacWarrior/clipbucket-v5/releases/tag/5.5.3-%23182"
        },
        {
          "name": "sort_link() in upload/includes/functions.php at 5.5.3-#153",
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/MacWarrior/clipbucket-v5/blob/5.5.3-%23153/upload/includes/functions.php"
        },
        {
          "name": "Reporter write-up",
          "tags": [
            "technical-description",
            "exploit"
          ],
          "url": "https://hackmd.io/@leediay/reflected-xss-in-search-function-clipbucket-v5"
        },
        {
          "tags": [
            "product"
          ],
          "url": "https://github.com/MacWarrior/clipbucket-v5"
        },
        {
          "name": "VulnCheck Advisory: ClipBucket v5 before 5.5.3-#182 Reflected XSS via Query Parameters",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/clipbucket-v5-before-5.5.3-182-reflected-xss-via-query-parameters"
        }
      ],
      "title": "ClipBucket v5 before 5.5.3-#182 Reflected XSS via Query Parameters",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-95812",
    "datePublished": "2026-09-22T20:21:10.251Z",
    "dateReserved": "2026-09-22T15:47:12.682Z",
    "dateUpdated": "2026-10-06T13:37:06.270Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-95682 (GCVE-0-2026-95682)

Vulnerability from cvelistv5 – Published: 2026-09-22 13:56 – Updated: 2026-09-22 15:31
VLAI
Title
MISP Stored Cross-Site Scripting via Unescaped Organization Name in Admin Email View
Summary
MISP contains a stored cross-site scripting (XSS) vulnerability in the admin email composition screen. The MISP.org organization name setting was interpolated directly into a JavaScript string literal using an unescaped PHP echo: var org = "<?php echo $org;?>";. Because the value was placed inside a double-quoted JavaScript string without any encoding, an organization name containing a double-quote character (or a backslash) could terminate the string literal and inject arbitrary JavaScript into the page. The injected script would execute in the context of any authenticated user who subsequently loads the admin email page, potentially allowing session hijacking, data exfiltration, or privileged actions performed on behalf of the victim. Exploitation requires the ability to set or modify the MISP.org organization name and a second authenticated user visiting the affected admin email view. The vulnerability is a classic instance of insufficient output encoding in a JavaScript context.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-22 15:31 UTC
CWE
  • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
References
Impacted products
Vendor Product Version
MISP MISP Affected: unspecified , < 2.5.47 (semver)
Create a notification for this product.
GCVE extensions
bcp-05-x-01
AI-assisted vulnerability information annotation
GCVE-BCP-05-X-01
Whole record AI-generated Human-reviewed GNA-1

Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.

ai-computer-assisted:llm-generatedai-computer-assisted:classification
Model Source Identifier
qwen3.8:27b ollama qwen3.8:27b
bcp-05-x-02
Patch-to-vulnerability generation provenance
GCVE-BCP-05-X-02
Generator
patch2vuln.py on 2026-09-22 13:52
Model
qwen3.8:27b
Input
https://github.com/MISP/MISP/commit/5d6ace65e.patch 9891167be879…
Confidence
high
Commit Subject Patch SHA-256
5d6ace65e1d5 fix: [ui] Escape MISP.org when it is echoed into the admin 9891167be879…
Fix summary

The fix replaces the raw PHP echo of the organization name with a json_encode() call using the flags JSON_HEX_TAG, JSON_HEX_AMP, JSON_HEX_APOS, and JSON_HEX_QUOT. This produces a properly escaped JavaScript string literal that neutralizes quotes, angle brackets, ampersands, and other metacharacters, preventing breakout from the string context and subsequent script injection.

Patch summary

In app/View/Users/admin_email.ctp, line 72, the expression var org = "<?php echo $org;?>"; is replaced with var org = <?php echo json_encode($org, JSON_HEX_TAG | JSON_HEX_AMP | JSON_HEX_APOS | JSON_HEX_QUOT); ?>;. The surrounding double quotes are removed because json_encode already emits a quoted string literal. The four JSON_HEX_* flags ensure that <, >, &, ', and " are hex-escaped, making the output safe for embedding in both HTML and JavaScript contexts.

CVSS rationale

AV:N: exploited over the network via a web application. AC:L: no race conditions or special timing; a single quote in the org name suffices. AT:N: no manipulation of the attack target required. PR:H: the attacker must have sufficient privileges to set the MISP.org organization name (assumed to be an admin-level capability). UI:P: the victim passively triggers the payload by navigating to the admin email page. VC:L / VI:L: the injected script can read page data, cookies, and perform actions in the victim's session, but is scoped to the MISP application. VA:N: no denial-of-service impact. SC:L / SI:L: limited sub-system impact via the victim's browser session. SA:N: no availability impact on the sub-system.

Weakness rationale
  • CWE-79 The organization name (attacker-influenced data) is written into a JavaScript string literal in an HTML page without context-appropriate encoding, allowing script breakout. This is a textbook stored XSS in a JavaScript context, which maps directly to CWE-79.
Attack pattern rationale
  • CAPEC-1 The patch demonstrates a stored XSS where attacker-controlled data (the MISP.org name) is reflected into a JavaScript context without encoding. CAPEC-1 is the canonical attack pattern for cross-site scripting. The mapping is direct and unambiguous given the commit message explicitly describes quote-breakout script injection.
Assumptions to verify
  • PR:H assumes that setting the MISP.org organization name requires administrative privileges; if a lower-privileged role can modify this setting, PR should be lowered.
  • The exact fixed version is not stated in the patch; the tag boundary (v2.5.47, 52 commits after fix) suggests the fix lands in a release after v2.5.47, but the precise version number is unconfirmed.
  • UI:P assumes the victim merely navigates to the admin email page (passive interaction); no click or form submission is required to trigger the stored script.
  • The CAPEC-1 mapping is direct; no uncertainty is noted because the commit message and diff unambiguously describe a stored XSS via unescaped output in a JavaScript context.
  • Impact metrics (VC:L, VI:L, SC:L, SI:L) assume the XSS is confined to the MISP application context and does not enable cross-origin data theft beyond what the victim's browser session already exposes.
Model comparison

Selected qwen3.8:27b by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.

Model Score Agreement Confidence Assumptions
qwen3.8:27b 6 9 high 5
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-95682",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-22T15:31:00.583552Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-22T15:31:09.389Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "modules": [
            "app/View/Users/admin_email.ctp"
          ],
          "product": "MISP",
          "programFiles": [
            "app/View/Users/admin_email.ctp"
          ],
          "repo": "https://github.com/MISP/MISP",
          "vendor": "MISP",
          "versions": [
            {
              "lessThan": "2.5.47",
              "status": "affected",
              "version": "unspecified",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "Jeroen Pinoy"
        },
        {
          "lang": "en",
          "type": "remediation developer",
          "value": "iglocska"
        },
        {
          "lang": "en",
          "type": "remediation developer",
          "value": "Claude Opus 4.8"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eMISP contains a stored cross-site scripting (XSS) vulnerability in the admin email composition screen. The MISP.org organization name setting was interpolated directly into a JavaScript string literal using an unescaped PHP echo: var org = \"\u0026lt;?php echo $org;?\u0026gt;\";. Because the value was placed inside a double-quoted JavaScript string without any encoding, an organization name containing a double-quote character (or a backslash) could terminate the string literal and inject arbitrary JavaScript into the page. The injected script would execute in the context of any authenticated user who subsequently loads the admin email page, potentially allowing session hijacking, data exfiltration, or privileged actions performed on behalf of the victim.\u003c/p\u003e\u003cp\u003eExploitation requires the ability to set or modify the MISP.org organization name and a second authenticated user visiting the affected admin email view.\u003c/p\u003e\u003cp\u003eThe vulnerability is a classic instance of insufficient output encoding in a JavaScript context.\u003c/p\u003e"
            }
          ],
          "value": "MISP contains a stored cross-site scripting (XSS) vulnerability in the admin email composition screen. The MISP.org organization name setting was interpolated directly into a JavaScript string literal using an unescaped PHP echo: var org = \"\u003c?php echo $org;?\u003e\";. Because the value was placed inside a double-quoted JavaScript string without any encoding, an organization name containing a double-quote character (or a backslash) could terminate the string literal and inject arbitrary JavaScript into the page. The injected script would execute in the context of any authenticated user who subsequently loads the admin email page, potentially allowing session hijacking, data exfiltration, or privileged actions performed on behalf of the victim.\n\nExploitation requires the ability to set or modify the MISP.org organization name and a second authenticated user visiting the affected admin email view.\n\nThe vulnerability is a classic instance of insufficient output encoding in a JavaScript context."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-1",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-1 Cross Site Scripting (XSS)"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "HIGH",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "LOW",
            "subIntegrityImpact": "LOW",
            "userInteraction": "PASSIVE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-79",
              "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-22T13:56:51.445Z",
        "orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
        "shortName": "CIRCL"
      },
      "references": [
        {
          "name": "Security patch",
          "tags": [
            "patch"
          ],
          "url": "https://github.com/MISP/MISP/commit/5d6ace65e"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eThe fix replaces the raw PHP echo of the organization name with a json_encode() call using the flags JSON_HEX_TAG, JSON_HEX_AMP, JSON_HEX_APOS, and JSON_HEX_QUOT. This produces a properly escaped JavaScript string literal that neutralizes quotes, angle brackets, ampersands, and other metacharacters, preventing breakout from the string context and subsequent script injection.\u003c/p\u003e"
            }
          ],
          "value": "The fix replaces the raw PHP echo of the organization name with a json_encode() call using the flags JSON_HEX_TAG, JSON_HEX_AMP, JSON_HEX_APOS, and JSON_HEX_QUOT. This produces a properly escaped JavaScript string literal that neutralizes quotes, angle brackets, ampersands, and other metacharacters, preventing breakout from the string context and subsequent script injection."
        }
      ],
      "title": "MISP Stored Cross-Site Scripting via Unescaped Organization Name in Admin Email View",
      "x_gcve": [
        {
          "extensions": {
            "bcp-05-x-01": {
              "ai_annotations": [
                {
                  "ai_level": "generated",
                  "description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
                  "gna_source": 1,
                  "models": [
                    {
                      "gna_source": 1,
                      "identifier": "qwen3.8:27b",
                      "name": "qwen3.8:27b",
                      "source": "ollama"
                    }
                  ],
                  "review_status": "full",
                  "scope": "record",
                  "tags": [
                    "ai-computer-assisted:llm-generated",
                    "ai-computer-assisted:classification"
                  ]
                }
              ]
            },
            "bcp-05-x-02": {
              "x_patch2vuln": {
                "assumptions": [
                  "PR:H assumes that setting the MISP.org organization name requires administrative privileges; if a lower-privileged role can modify this setting, PR should be lowered.",
                  "The exact fixed version is not stated in the patch; the tag boundary (v2.5.47, 52 commits after fix) suggests the fix lands in a release after v2.5.47, but the precise version number is unconfirmed.",
                  "UI:P assumes the victim merely navigates to the admin email page (passive interaction); no click or form submission is required to trigger the stored script.",
                  "The CAPEC-1 mapping is direct; no uncertainty is noted because the commit message and diff unambiguously describe a stored XSS via unescaped output in a JavaScript context.",
                  "Impact metrics (VC:L, VI:L, SC:L, SI:L) assume the XSS is confined to the MISP application context and does not enable cross-origin data theft beyond what the victim\u0027s browser session already exposes."
                ],
                "capecRationale": [
                  {
                    "capecId": "CAPEC-1",
                    "rationale": "The patch demonstrates a stored XSS where attacker-controlled data (the MISP.org name) is reflected into a JavaScript context without encoding. CAPEC-1 is the canonical attack pattern for cross-site scripting. The mapping is direct and unambiguous given the commit message explicitly describes quote-breakout script injection."
                  }
                ],
                "commit": "5d6ace65e1d523dcbf04ce405a2f3a833cd353b2",
                "confidence": "high",
                "credits": [
                  {
                    "lang": "en",
                    "type": "reporter",
                    "value": "Jeroen Pinoy"
                  },
                  {
                    "lang": "en",
                    "type": "remediation developer",
                    "value": "iglocska"
                  },
                  {
                    "lang": "en",
                    "type": "remediation developer",
                    "value": "Claude Opus 4.8"
                  }
                ],
                "cvssRationale": "AV:N: exploited over the network via a web application. AC:L: no race conditions or special timing; a single quote in the org name suffices. AT:N: no manipulation of the attack target required. PR:H: the attacker must have sufficient privileges to set the MISP.org organization name (assumed to be an admin-level capability). UI:P: the victim passively triggers the payload by navigating to the admin email page. VC:L / VI:L: the injected script can read page data, cookies, and perform actions in the victim\u0027s session, but is scoped to the MISP application. VA:N: no denial-of-service impact. SC:L / SI:L: limited sub-system impact via the victim\u0027s browser session. SA:N: no availability impact on the sub-system.",
                "fixSummary": "The fix replaces the raw PHP echo of the organization name with a json_encode() call using the flags JSON_HEX_TAG, JSON_HEX_AMP, JSON_HEX_APOS, and JSON_HEX_QUOT. This produces a properly escaped JavaScript string literal that neutralizes quotes, angle brackets, ampersands, and other metacharacters, preventing breakout from the string context and subsequent script injection.",
                "generatedAt": "2026-09-22T13:52:55.463303Z",
                "generator": "patch2vuln.py",
                "model": "qwen3.8:27b",
                "modelComparison": {
                  "rankings": [
                    {
                      "agreementScore": 9,
                      "assumptionCount": 5,
                      "confidence": "high",
                      "model": "qwen3.8:27b",
                      "score": 6
                    }
                  ],
                  "selectedModel": "qwen3.8:27b",
                  "selectionMethod": "deterministic-consensus-v1",
                  "selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
                },
                "patchSha256": "9891167be879e4192e2ddd15347138945efa2bb402c49e7304af1b67f02a054b",
                "patchSummary": "In app/View/Users/admin_email.ctp, line 72, the expression var org = \"\u003c?php echo $org;?\u003e\"; is replaced with var org = \u003c?php echo json_encode($org, JSON_HEX_TAG | JSON_HEX_AMP | JSON_HEX_APOS | JSON_HEX_QUOT); ?\u003e;. The surrounding double quotes are removed because json_encode already emits a quoted string literal. The four JSON_HEX_* flags ensure that \u003c, \u003e, \u0026, \u0027, and \" are hex-escaped, making the output safe for embedding in both HTML and JavaScript contexts.",
                "patchTruncated": false,
                "patches": [
                  {
                    "commit": "5d6ace65e1d523dcbf04ce405a2f3a833cd353b2",
                    "patchSha256": "9891167be879e4192e2ddd15347138945efa2bb402c49e7304af1b67f02a054b",
                    "source": "https://github.com/MISP/MISP/commit/5d6ace65e.patch",
                    "sourceUrl": "https://github.com/MISP/MISP/commit/5d6ace65e.patch",
                    "subject": "fix: [ui] Escape MISP.org when it is echoed into the admin"
                  }
                ],
                "source": "https://github.com/MISP/MISP/commit/5d6ace65e.patch",
                "subject": "fix: [ui] Escape MISP.org when it is echoed into the admin",
                "tagVersionBoundary": {
                  "commits_after_fix": 52,
                  "repository": "https://github.com/MISP/MISP",
                  "tag": "v2.5.47",
                  "version": "2.5.47",
                  "version_type": "semver"
                },
                "weaknessRationale": [
                  {
                    "cweId": "CWE-79",
                    "rationale": "The organization name (attacker-influenced data) is written into a JavaScript string literal in an HTML page without context-appropriate encoding, allowing script breakout. This is a textbook stored XSS in a JavaScript context, which maps directly to CWE-79."
                  }
                ]
              }
            }
          },
          "recordType": "advisory",
          "vulnId": "GCVE-1-2026-20214"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
    "assignerShortName": "CIRCL",
    "cveId": "CVE-2026-95682",
    "datePublished": "2026-09-22T13:56:51.445Z",
    "dateReserved": "2026-09-22T13:56:48.812Z",
    "dateUpdated": "2026-09-22T15:31:09.389Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-95670 (GCVE-0-2026-95670)

Vulnerability from cvelistv5 – Published: 2026-10-02 07:39 – Updated: 2026-10-03 15:42
VLAI
Title
No External Links <= 5.2.0 - Unauthenticated Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect
Summary
The No External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect in all versions up to, and including, 5.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the administrator has enabled the 'Link Encoding: Base64' option in the plugin settings.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-03 15:30 UTC
CWE
  • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Impacted products
Vendor Product Version
mihdan No External Links Affected: 0 , ≤ 5.2.0 (semver)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-95670",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-03T15:30:06.468542Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-03T15:42:48.848Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "No External Links",
          "vendor": "mihdan",
          "versions": [
            {
              "lessThanOrEqual": "5.2.0",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Afifudin Maarif"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "The No External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect in all versions up to, and including, 5.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the administrator has enabled the \u0027Link Encoding: Base64\u0027 option in the plugin settings."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-79",
              "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-02T07:39:27.705Z",
        "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "shortName": "Wordfence"
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ab5a9850-8990-4e24-9ac3-5b92564c4ad9?source=cve"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mihdan-no-external-links/tags/5.2.0/admin/LogTable.php#L95"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mihdan-no-external-links/tags/5.2.0/public/Frontend.php#L989"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mihdan-no-external-links/tags/5.2.0/public/Frontend.php#L801"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/mihdan-no-external-links/tags/5.2.0/public/Frontend.php#L451"
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3719796%40mihdan-no-external-links\u0026new=3719796%40mihdan-no-external-links"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-22T13:34:10.000Z",
          "value": "Vendor Notified"
        },
        {
          "lang": "en",
          "time": "2026-10-01T19:17:12.000Z",
          "value": "Disclosed"
        }
      ],
      "title": "No External Links \u003c= 5.2.0 - Unauthenticated Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
    "assignerShortName": "Wordfence",
    "cveId": "CVE-2026-95670",
    "datePublished": "2026-10-02T07:39:27.705Z",
    "dateReserved": "2026-09-22T13:19:05.691Z",
    "dateUpdated": "2026-10-03T15:42:48.848Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-95665 (GCVE-0-2026-95665)

Vulnerability from cvelistv5 – Published: 2026-09-22 13:01 – Updated: 2026-09-22 15:33
VLAI
Title
MISP Reflected Cross-Site Scripting in Event Export Confirmation Form via Unescaped JSON
Summary
MISP contains a reflected cross-site scripting (XSS) vulnerability in the event REST search export confirmation form. The view template app/View/Events/ajax/eventRestSearchExportConfirmationForm.ctp renders a URL-supplied event ID list into a single-quoted JavaScript string literal using PHP's json_encode() without any hex-encoding flags. By default, json_encode() escapes double quotes and backslashes but does not escape single quotes. Because the JavaScript string is delimited by single quotes, an attacker can inject a single-quote character to terminate the string literal and execute arbitrary JavaScript in the victim's browser session. The vulnerability affects the Default and UiBeta themes, both of which render this view. The Overmind theme's own copy of the form already passed the value through an escaped data attribute and was not affected by this specific sink. Preconditions: the victim must be an authenticated MISP user and must actively open or navigate to the attacker-crafted URL. The attacker does not require an account or any prior access to the MISP instance. Security impact: successful exploitation allows execution of arbitrary JavaScript in the context of the MISP web application, potentially leading to session hijacking, unauthorized actions performed on behalf of the victim, exfiltration of sensitive data visible in the session, or further client-side attacks. The vulnerable component's own confidentiality, integrity, and availability are not directly compromised; the impact is on the underlying user session.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-22 15:32 UTC
CWE
  • CWE-79 - Improper Neutralization of Input in Web Page ('Cross-site Scripting')
References
Impacted products
Vendor Product Version
MISP MISP Affected: 0 , < 2.5.47 (semver)
Create a notification for this product.
GCVE extensions
bcp-05-x-01
AI-assisted vulnerability information annotation
GCVE-BCP-05-X-01
Whole record AI-generated Human-reviewed GNA-1

Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.

ai-computer-assisted:llm-generatedai-computer-assisted:classification
Model Source Identifier
qwen3.8:27b ollama qwen3.8:27b
bcp-05-x-02
Patch-to-vulnerability generation provenance
GCVE-BCP-05-X-02
Generator
patch2vuln.py on 2026-09-22 12:57
Model
qwen3.8:27b
Input
https://github.com/MISP/MISP/commit/ad4ff238d.patch b2c68a624115…
Confidence
high
Commit Subject Patch SHA-256
ad4ff238df97 fix: [security] Escape the event id list in the export b2c68a624115…
Fix summary

The vulnerability is remediated by adding the JSON_HEX_TAG, JSON_HEX_APOS, JSON_HEX_QUOT, and JSON_HEX_AMP flags to the json_encode() call at the rendering sink. These flags cause angle brackets, single quotes, double quotes, and ampersands to be hex-encoded (e.g., ' becomes \u0027), preventing any of these characters from breaking out of the single-quoted JavaScript string literal and thereby eliminating the script injection vector.

Patch summary

A single-line change in app/View/Events/ajax/eventRestSearchExportConfirmationForm.ctp: the json_encode($idList) call is replaced with json_encode($idList, JSON_HEX_TAG | JSON_HEX_APOS | JSON_HEX_QUOT | JSON_HEX_AMP), ensuring that single quotes, double quotes, angle brackets, and ampersands in the event ID list are hex-escaped before being interpolated into the single-quoted JavaScript string literal in the redirectToExportResult() function.

CVSS rationale

AV:N: the exploit is delivered over the network via a crafted URL. AC:L: the attack requires only crafting a URL with a single quote in the event ID list; no race conditions or special conditions are needed. AT:N: no additional attack complexity beyond what AC captures. PR:N: the attacker does not need any MISP account or privileges; the victim must be authenticated, but PR measures attacker privileges. UI:A: the victim must actively open or click the crafted link. VC/VI/VA:N: the MISP server's own confidentiality, integrity, and availability are not directly impacted. SC:L: the attacker can read session data, cookies, or other sensitive information in the victim's browser context. SI:L: the attacker can perform actions on behalf of the victim (e.g., submit forms, modify data via the API). SA:N: no impact on the availability of the underlying system.

Weakness rationale
  • CWE-79 The root cause is the failure to neutralize a single-quote character in user-controlled input (the URL-supplied event ID list) before embedding it in a single-quoted JavaScript string context. json_encode() without hex flags does not escape single quotes, allowing script injection. This is a textbook reflected XSS (CWE-79).
Attack pattern rationale
  • CAPEC-1 The attack pattern involves injecting a script fragment (a single quote followed by arbitrary JavaScript) into a web page via a URL parameter, which is then reflected into the page's JavaScript context without proper encoding. This matches CAPEC-1 (Cross Site Scripting) directly. The injection is reflected (not stored) and occurs in a script context rather than an HTML context, but CAPEC-1 is the closest and most general applicable pattern. No more specific CAPEC for script-context reflected XSS exists in the CAPEC catalog, so CAPEC-1 is the best available match.
Assumptions to verify
  • The tag_version_boundary metadata indicates the fix commit is 44 commits after tag v2.5.47, suggesting versions up to and including 2.5.47 may be affected, but no explicit affected or fixed version range is stated in the patch or commit message. The version boundary is inferred from repository metadata and may not be precise.
  • The CVSS v4.0 AT (Attack Complexity) metric value 'N' is used as the neutral/none value; the exact valid value set for AT in CVSS v4.0 is not fully confirmed from the patch evidence alone.
  • The CAPEC-1 mapping is the closest general XSS pattern available; no CAPEC specifically covers script-context reflected XSS via unescaped JSON in a single-quoted JS string, so CAPEC-1 is the best available match.
  • The Overmind theme is assumed unaffected because the commit message states it already passed the value through an escaped data attribute; this is based solely on the commit message and was not independently verified.
  • PR:N is assigned because the attacker does not require authentication to craft the malicious URL; the requirement that the victim be logged in is captured in UI:A rather than PR.
Model comparison

Selected qwen3.8:27b by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.

Model Score Agreement Confidence Assumptions
qwen3.8:27b 6 9 high 5
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-95665",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-22T15:32:57.787316Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-22T15:33:05.484Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "modules": [
            "Events export confirmation form (app/View/Events/ajax/eventRestSearchExportConfirmationForm.ctp)",
            "Default theme",
            "UiBeta theme"
          ],
          "product": "MISP",
          "programFiles": [
            "app/View/Events/ajax/eventRestSearchExportConfirmationForm.ctp"
          ],
          "repo": "https://github.com/MISP/MISP",
          "vendor": "MISP",
          "versions": [
            {
              "lessThan": "2.5.47",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "Niels Teusink of Eye Security"
        },
        {
          "lang": "en",
          "type": "remediation developer",
          "value": "iglocska"
        },
        {
          "lang": "en",
          "type": "remediation developer",
          "value": "Claude Opus 5 (1M context)"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eMISP contains a reflected cross-site scripting (XSS) vulnerability in the event REST search export confirmation form. The view template app/View/Events/ajax/eventRestSearchExportConfirmationForm.ctp renders a URL-supplied event ID list into a single-quoted JavaScript string literal using PHP\u0027s json_encode() without any hex-encoding flags. By default, json_encode() escapes double quotes and backslashes but does not escape single quotes. Because the JavaScript string is delimited by single quotes, an attacker can inject a single-quote character to terminate the string literal and execute arbitrary JavaScript in the victim\u0027s browser session.\u003c/p\u003e\u003cp\u003eThe vulnerability affects the Default and UiBeta themes, both of which render this view. The Overmind theme\u0027s own copy of the form already passed the value through an escaped data attribute and was not affected by this specific sink.\u003c/p\u003e\u003cp\u003ePreconditions: the victim must be an authenticated MISP user and must actively open or navigate to the attacker-crafted URL. The attacker does not require an account or any prior access to the MISP instance.\u003c/p\u003e\u003cp\u003eSecurity impact: successful exploitation allows execution of arbitrary JavaScript in the context of the MISP web application, potentially leading to session hijacking, unauthorized actions performed on behalf of the victim, exfiltration of sensitive data visible in the session, or further client-side attacks. The vulnerable component\u0027s own confidentiality, integrity, and availability are not directly compromised; the impact is on the underlying user session.\u003c/p\u003e"
            }
          ],
          "value": "MISP contains a reflected cross-site scripting (XSS) vulnerability in the event REST search export confirmation form. The view template app/View/Events/ajax/eventRestSearchExportConfirmationForm.ctp renders a URL-supplied event ID list into a single-quoted JavaScript string literal using PHP\u0027s json_encode() without any hex-encoding flags. By default, json_encode() escapes double quotes and backslashes but does not escape single quotes. Because the JavaScript string is delimited by single quotes, an attacker can inject a single-quote character to terminate the string literal and execute arbitrary JavaScript in the victim\u0027s browser session.\n\nThe vulnerability affects the Default and UiBeta themes, both of which render this view. The Overmind theme\u0027s own copy of the form already passed the value through an escaped data attribute and was not affected by this specific sink.\n\nPreconditions: the victim must be an authenticated MISP user and must actively open or navigate to the attacker-crafted URL. The attacker does not require an account or any prior access to the MISP instance.\n\nSecurity impact: successful exploitation allows execution of arbitrary JavaScript in the context of the MISP web application, potentially leading to session hijacking, unauthorized actions performed on behalf of the victim, exfiltration of sensitive data visible in the session, or further client-side attacks. The vulnerable component\u0027s own confidentiality, integrity, and availability are not directly compromised; the impact is on the underlying user session."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-1",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-1 Cross Site Scripting"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 5.1,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "LOW",
            "subIntegrityImpact": "LOW",
            "userInteraction": "ACTIVE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-79",
              "description": "CWE-79 Improper Neutralization of Input in Web Page (\u0027Cross-site Scripting\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-22T13:01:45.225Z",
        "orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
        "shortName": "CIRCL"
      },
      "references": [
        {
          "name": "Security patch",
          "tags": [
            "patch"
          ],
          "url": "https://github.com/MISP/MISP/commit/ad4ff238d"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eThe vulnerability is remediated by adding the JSON_HEX_TAG, JSON_HEX_APOS, JSON_HEX_QUOT, and JSON_HEX_AMP flags to the json_encode() call at the rendering sink. These flags cause angle brackets, single quotes, double quotes, and ampersands to be hex-encoded (e.g., \u0027 becomes \\u0027), preventing any of these characters from breaking out of the single-quoted JavaScript string literal and thereby eliminating the script injection vector.\u003c/p\u003e"
            }
          ],
          "value": "The vulnerability is remediated by adding the JSON_HEX_TAG, JSON_HEX_APOS, JSON_HEX_QUOT, and JSON_HEX_AMP flags to the json_encode() call at the rendering sink. These flags cause angle brackets, single quotes, double quotes, and ampersands to be hex-encoded (e.g., \u0027 becomes \\u0027), preventing any of these characters from breaking out of the single-quoted JavaScript string literal and thereby eliminating the script injection vector."
        }
      ],
      "title": "MISP Reflected Cross-Site Scripting in Event Export Confirmation Form via Unescaped JSON",
      "x_gcve": [
        {
          "extensions": {
            "bcp-05-x-01": {
              "ai_annotations": [
                {
                  "ai_level": "generated",
                  "description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
                  "gna_source": 1,
                  "models": [
                    {
                      "gna_source": 1,
                      "identifier": "qwen3.8:27b",
                      "name": "qwen3.8:27b",
                      "source": "ollama"
                    }
                  ],
                  "review_status": "full",
                  "scope": "record",
                  "tags": [
                    "ai-computer-assisted:llm-generated",
                    "ai-computer-assisted:classification"
                  ]
                }
              ]
            },
            "bcp-05-x-02": {
              "x_patch2vuln": {
                "assumptions": [
                  "The tag_version_boundary metadata indicates the fix commit is 44 commits after tag v2.5.47, suggesting versions up to and including 2.5.47 may be affected, but no explicit affected or fixed version range is stated in the patch or commit message. The version boundary is inferred from repository metadata and may not be precise.",
                  "The CVSS v4.0 AT (Attack Complexity) metric value \u0027N\u0027 is used as the neutral/none value; the exact valid value set for AT in CVSS v4.0 is not fully confirmed from the patch evidence alone.",
                  "The CAPEC-1 mapping is the closest general XSS pattern available; no CAPEC specifically covers script-context reflected XSS via unescaped JSON in a single-quoted JS string, so CAPEC-1 is the best available match.",
                  "The Overmind theme is assumed unaffected because the commit message states it already passed the value through an escaped data attribute; this is based solely on the commit message and was not independently verified.",
                  "PR:N is assigned because the attacker does not require authentication to craft the malicious URL; the requirement that the victim be logged in is captured in UI:A rather than PR."
                ],
                "capecRationale": [
                  {
                    "capecId": "CAPEC-1",
                    "rationale": "The attack pattern involves injecting a script fragment (a single quote followed by arbitrary JavaScript) into a web page via a URL parameter, which is then reflected into the page\u0027s JavaScript context without proper encoding. This matches CAPEC-1 (Cross Site Scripting) directly. The injection is reflected (not stored) and occurs in a script context rather than an HTML context, but CAPEC-1 is the closest and most general applicable pattern. No more specific CAPEC for script-context reflected XSS exists in the CAPEC catalog, so CAPEC-1 is the best available match."
                  }
                ],
                "commit": "ad4ff238df978d459ac6efe0a58038748fa4a649",
                "confidence": "high",
                "credits": [
                  {
                    "lang": "en",
                    "type": "reporter",
                    "value": "Niels Teusink of Eye Security"
                  },
                  {
                    "lang": "en",
                    "type": "remediation developer",
                    "value": "iglocska"
                  },
                  {
                    "lang": "en",
                    "type": "remediation developer",
                    "value": "Claude Opus 5 (1M context)"
                  }
                ],
                "cvssRationale": "AV:N: the exploit is delivered over the network via a crafted URL. AC:L: the attack requires only crafting a URL with a single quote in the event ID list; no race conditions or special conditions are needed. AT:N: no additional attack complexity beyond what AC captures. PR:N: the attacker does not need any MISP account or privileges; the victim must be authenticated, but PR measures attacker privileges. UI:A: the victim must actively open or click the crafted link. VC/VI/VA:N: the MISP server\u0027s own confidentiality, integrity, and availability are not directly impacted. SC:L: the attacker can read session data, cookies, or other sensitive information in the victim\u0027s browser context. SI:L: the attacker can perform actions on behalf of the victim (e.g., submit forms, modify data via the API). SA:N: no impact on the availability of the underlying system.",
                "fixSummary": "The vulnerability is remediated by adding the JSON_HEX_TAG, JSON_HEX_APOS, JSON_HEX_QUOT, and JSON_HEX_AMP flags to the json_encode() call at the rendering sink. These flags cause angle brackets, single quotes, double quotes, and ampersands to be hex-encoded (e.g., \u0027 becomes \\u0027), preventing any of these characters from breaking out of the single-quoted JavaScript string literal and thereby eliminating the script injection vector.",
                "generatedAt": "2026-09-22T12:57:11.104186Z",
                "generator": "patch2vuln.py",
                "model": "qwen3.8:27b",
                "modelComparison": {
                  "rankings": [
                    {
                      "agreementScore": 9,
                      "assumptionCount": 5,
                      "confidence": "high",
                      "model": "qwen3.8:27b",
                      "score": 6
                    }
                  ],
                  "selectedModel": "qwen3.8:27b",
                  "selectionMethod": "deterministic-consensus-v1",
                  "selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
                },
                "patchSha256": "b2c68a62411584c586558a3ab03529c380d9bdb0824ac292b26e7f8b3278fa01",
                "patchSummary": "A single-line change in app/View/Events/ajax/eventRestSearchExportConfirmationForm.ctp: the json_encode($idList) call is replaced with json_encode($idList, JSON_HEX_TAG | JSON_HEX_APOS | JSON_HEX_QUOT | JSON_HEX_AMP), ensuring that single quotes, double quotes, angle brackets, and ampersands in the event ID list are hex-escaped before being interpolated into the single-quoted JavaScript string literal in the redirectToExportResult() function.",
                "patchTruncated": false,
                "patches": [
                  {
                    "commit": "ad4ff238df978d459ac6efe0a58038748fa4a649",
                    "patchSha256": "b2c68a62411584c586558a3ab03529c380d9bdb0824ac292b26e7f8b3278fa01",
                    "source": "https://github.com/MISP/MISP/commit/ad4ff238d.patch",
                    "sourceUrl": "https://github.com/MISP/MISP/commit/ad4ff238d.patch",
                    "subject": "fix: [security] Escape the event id list in the export"
                  }
                ],
                "source": "https://github.com/MISP/MISP/commit/ad4ff238d.patch",
                "subject": "fix: [security] Escape the event id list in the export",
                "tagVersionBoundary": {
                  "commits_after_fix": 44,
                  "repository": "https://github.com/MISP/MISP",
                  "tag": "v2.5.47",
                  "version": "2.5.47",
                  "version_type": "semver"
                },
                "weaknessRationale": [
                  {
                    "cweId": "CWE-79",
                    "rationale": "The root cause is the failure to neutralize a single-quote character in user-controlled input (the URL-supplied event ID list) before embedding it in a single-quoted JavaScript string context. json_encode() without hex flags does not escape single quotes, allowing script injection. This is a textbook reflected XSS (CWE-79)."
                  }
                ]
              }
            }
          },
          "recordType": "advisory",
          "vulnId": "GCVE-1-2026-20129"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
    "assignerShortName": "CIRCL",
    "cveId": "CVE-2026-95665",
    "datePublished": "2026-09-22T13:01:45.225Z",
    "dateReserved": "2026-09-22T13:01:42.885Z",
    "dateUpdated": "2026-09-22T15:33:05.484Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-95662 (GCVE-0-2026-95662)

Vulnerability from cvelistv5 – Published: 2026-10-02 09:51 – Updated: 2026-10-02 17:51
VLAI
Title
Multiple vulnerabilities in the Repasat application
Summary
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomCompetidor” parameter is affected – endpoint “/es/competitors/store”.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-02 17:51 UTC
CWE
  • CWE-79 - Improper neutralization of input during web page generation ('cross-site scripting')
Impacted products
Vendor Product Version
Repasat Repasat application Affected: 0 , < Abril patch "20260402" (custom)
Create a notification for this product.
Date Public
2026-10-02 09:48
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-95662",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-02T17:51:03.460301Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-02T17:51:19.695Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Repasat application",
          "vendor": "Repasat",
          "versions": [
            {
              "lessThan": "Abril patch \"20260402\"",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "David Padilla Alvarado"
        }
      ],
      "datePublic": "2026-10-02T09:48:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim\u2019s browser. The \u201cnomCompetidor\u201d parameter is affected \u2013 endpoint \u201c/es/competitors/store\u201d."
            }
          ],
          "value": "Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim\u2019s browser. The \u201cnomCompetidor\u201d parameter is affected \u2013 endpoint \u201c/es/competitors/store\u201d."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "ACTIVE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-79",
              "description": "CWE-79 Improper neutralization of input during web page generation (\u0027cross-site scripting\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-02T09:51:31.849Z",
        "orgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516",
        "shortName": "INCIBE"
      },
      "references": [
        {
          "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-repasat-application"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "The vulnerabilities have been fixed in the April patch version \u201820260402\u2019."
            }
          ],
          "value": "The vulnerabilities have been fixed in the April patch version \u201820260402\u2019."
        }
      ],
      "source": {
        "discovery": "EXTERNAL"
      },
      "title": "Multiple vulnerabilities in the Repasat application",
      "x_generator": {
        "engine": "Vulnogram 1.0.5"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516",
    "assignerShortName": "INCIBE",
    "cveId": "CVE-2026-95662",
    "datePublished": "2026-10-02T09:51:31.849Z",
    "dateReserved": "2026-09-22T12:55:11.003Z",
    "dateUpdated": "2026-10-02T17:51:19.695Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-95661 (GCVE-0-2026-95661)

Vulnerability from cvelistv5 – Published: 2026-09-22 12:54 – Updated: 2026-09-22 15:34
VLAI
Title
MISP Reflected Cross-Site Scripting in Attribute Histogram via Unescaped URL-Supplied Type List
Summary
MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes variable, which is derived from the URL path segment , was interpolated directly into a JavaScript array literal inside an onClick HTML attribute without any encoding or escaping. An attacker who can cause an authenticated MISP user to visit a crafted URL containing a malicious type value can execute arbitrary JavaScript in the victim's browser within the MISP application origin. Successful exploitation allows the attacker to read session cookies, perform actions on behalf of the victim, or exfiltrate sensitive data accessible from the MISP interface.  The vulnerability requires the victim to be authenticated and to actively navigate to the attacker-supplied URL.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-22 15:33 UTC
CWE
  • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
References
Impacted products
Vendor Product Version
MISP MISP Affected: 0 , < 2.5.47 (semver)
Create a notification for this product.
GCVE extensions
bcp-05-x-01
AI-assisted vulnerability information annotation
GCVE-BCP-05-X-01
Whole record AI-generated Human-reviewed GNA-1

Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.

ai-computer-assisted:llm-generatedai-computer-assisted:classification
Model Source Identifier
qwen3.8:27b ollama qwen3.8:27b
bcp-05-x-02
Patch-to-vulnerability generation provenance
GCVE-BCP-05-X-02
Generator
patch2vuln.py on 2026-09-22 12:45
Model
qwen3.8:27b
Input
https://github.com/MISP/MISP/commit/95b8f21f6.patch 33d145872395…
Confidence
high
Commit Subject Patch SHA-256
95b8f21f6be9 fix: [security] Escape the selected types in the attribute 33d145872395…
Fix summary

The fix replaces the unsafe raw PHP loop that concatenated type values into a JavaScript array literal with a call to json_encode() using the JSON_HEX_TAG, JSON_HEX_APOS, JSON_HEX_QUOT, and JSON_HEX_AMP flags. This ensures that all special characters (angle brackets, quotes, ampersands) in the type values are hex-encoded, preventing any value from breaking out of the JavaScript string/array context and injecting arbitrary script.

Patch summary

In app/View/Elements/histogram.ctp, the onClick attribute previously built a JS array by iterating over $selectedTypes and echoing each value between double quotes with no escaping: [<?php foreach ($selectedTypes as $t) echo '"' . $t . '", ' ?>]. The patch replaces this with a single json_encode($selectedTypes, JSON_HEX_TAG | JSON_HEX_APOS | JSON_HEX_QUOT | JSON_HEX_AMP) call, producing a safely encoded JSON array literal that cannot be broken out of by any element value.

CVSS rationale

AV:N: The vulnerability is exploitable over the network via a crafted URL. AC:L: No race conditions or special environment conditions are required; the attacker simply crafts a URL with a malicious type value. AT:N: No manipulation of the attack target is needed. PR:N: The attacker requires no privileges on the MISP instance; the victim must be authenticated, but that is a precondition on the victim, not a privilege requirement on the attacker. UI:A: The victim must actively click a link or navigate to the attacker-supplied URL for the reflected payload to execute. VC:N, VI:N, VA:N: The MISP server itself is not directly compromised; the impact is confined to the victim's browser session. SC:L: The attacker can read session tokens or data visible in the MISP UI within the victim's browser. SI:L: The attacker can perform actions on behalf of the victim within the MISP application. SA:N: No availability impact on the victim's browser or the MISP server.

Weakness rationale
  • CWE-79 The patch directly addresses the reflection of untrusted, URL-supplied data into a JavaScript context within an HTML attribute without encoding. This is a textbook reflected XSS (CWE-79). The specific sub-type is reflected XSS in a JavaScript context (inline event handler), but CWE-79 is the standard and most precise mapping.
Attack pattern rationale
  • CAPEC-1 CAPEC-1 is the canonical CAPEC pattern for cross-site scripting attacks, covering reflected, stored, and DOM-based variants. The patch evidence shows a reflected XSS where URL-supplied data is injected into an inline JavaScript event handler. CAPEC-1 is the closest and most direct match. No more specific CAPEC sub-pattern for reflected XSS in inline JS handlers exists in the CAPEC catalog, so CAPEC-1 is the best available mapping.
Assumptions to verify
  • The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.47 with 46 commits after the fix); the exact first affected version is not stated in the patch and is assumed to be all versions prior to the fix commit.
  • The UI:A (Active) rating assumes the victim must click a link or manually navigate to the crafted URL; if the URL could be triggered via an auto-redirect or embedded iframe, UI:P (Passive) might be more appropriate.
  • SC:L and SI:L are conservative ratings for the secondary-system impact; a full session hijack or data exfiltration could justify SC:H/SI:H, but the patch evidence does not specify the exact scope of exploitable data.
  • The CAPEC-1 mapping is the closest available pattern; no CAPEC sub-pattern specifically covers reflected XSS in inline JavaScript event handlers, so the general XSS pattern is used.
  • The commit message references 'any logged-in victim,' implying authentication is required; the exact role or permission level of the victim is not specified.
Model comparison

Selected qwen3.8:27b by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.

Model Score Agreement Confidence Assumptions
qwen3.8:27b 6 9 high 5
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-95661",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-22T15:33:57.327364Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-22T15:34:06.853Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "modules": [
            "app/View/Elements/histogram.ctp"
          ],
          "product": "MISP",
          "programFiles": [
            "app/View/Elements/histogram.ctp"
          ],
          "repo": "https://github.com/MISP/MISP",
          "vendor": "MISP",
          "versions": [
            {
              "lessThan": "2.5.47",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "Jeroen Pinoy"
        },
        {
          "lang": "en",
          "type": "remediation developer",
          "value": "iglocska"
        },
        {
          "lang": "en",
          "type": "remediation developer",
          "value": "Claude Opus 4.8"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eMISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes variable, which is derived from the URL path segment , was interpolated directly into a JavaScript array literal inside an onClick HTML attribute without any encoding or escaping. An attacker who can cause an authenticated MISP user to visit a crafted URL containing a malicious type value can execute arbitrary JavaScript in the victim\u0027s browser within the MISP application origin.\u003c/p\u003e\u003cp\u003eSuccessful exploitation allows the attacker to read session cookies, perform actions on behalf of the victim, or exfiltrate sensitive data accessible from the MISP interface.\u0026nbsp;\u003c/p\u003e\u003cp\u003eThe vulnerability requires the victim to be authenticated and to actively navigate to the attacker-supplied URL.\u003c/p\u003e"
            }
          ],
          "value": "MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes variable, which is derived from the URL path segment , was interpolated directly into a JavaScript array literal inside an onClick HTML attribute without any encoding or escaping. An attacker who can cause an authenticated MISP user to visit a crafted URL containing a malicious type value can execute arbitrary JavaScript in the victim\u0027s browser within the MISP application origin.\n\nSuccessful exploitation allows the attacker to read session cookies, perform actions on behalf of the victim, or exfiltrate sensitive data accessible from the MISP interface.\u00a0\n\nThe vulnerability requires the victim to be authenticated and to actively navigate to the attacker-supplied URL."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-1",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-1 Cross Site Scripting (XSS)"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 5.1,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "LOW",
            "subIntegrityImpact": "LOW",
            "userInteraction": "ACTIVE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-79",
              "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-22T12:54:46.496Z",
        "orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
        "shortName": "CIRCL"
      },
      "references": [
        {
          "name": "Security patch",
          "tags": [
            "patch"
          ],
          "url": "https://github.com/MISP/MISP/commit/95b8f21f6"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eThe fix replaces the unsafe raw PHP loop that concatenated type values into a JavaScript array literal with a call to json_encode() using the JSON_HEX_TAG, JSON_HEX_APOS, JSON_HEX_QUOT, and JSON_HEX_AMP flags. This ensures that all special characters (angle brackets, quotes, ampersands) in the type values are hex-encoded, preventing any value from breaking out of the JavaScript string/array context and injecting arbitrary script.\u003c/p\u003e"
            }
          ],
          "value": "The fix replaces the unsafe raw PHP loop that concatenated type values into a JavaScript array literal with a call to json_encode() using the JSON_HEX_TAG, JSON_HEX_APOS, JSON_HEX_QUOT, and JSON_HEX_AMP flags. This ensures that all special characters (angle brackets, quotes, ampersands) in the type values are hex-encoded, preventing any value from breaking out of the JavaScript string/array context and injecting arbitrary script."
        }
      ],
      "title": "MISP Reflected Cross-Site Scripting in Attribute Histogram via Unescaped URL-Supplied Type List",
      "x_gcve": [
        {
          "extensions": {
            "bcp-05-x-01": {
              "ai_annotations": [
                {
                  "ai_level": "generated",
                  "description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
                  "gna_source": 1,
                  "models": [
                    {
                      "gna_source": 1,
                      "identifier": "qwen3.8:27b",
                      "name": "qwen3.8:27b",
                      "source": "ollama"
                    }
                  ],
                  "review_status": "full",
                  "scope": "record",
                  "tags": [
                    "ai-computer-assisted:llm-generated",
                    "ai-computer-assisted:classification"
                  ]
                }
              ]
            },
            "bcp-05-x-02": {
              "x_patch2vuln": {
                "assumptions": [
                  "The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.47 with 46 commits after the fix); the exact first affected version is not stated in the patch and is assumed to be all versions prior to the fix commit.",
                  "The UI:A (Active) rating assumes the victim must click a link or manually navigate to the crafted URL; if the URL could be triggered via an auto-redirect or embedded iframe, UI:P (Passive) might be more appropriate.",
                  "SC:L and SI:L are conservative ratings for the secondary-system impact; a full session hijack or data exfiltration could justify SC:H/SI:H, but the patch evidence does not specify the exact scope of exploitable data.",
                  "The CAPEC-1 mapping is the closest available pattern; no CAPEC sub-pattern specifically covers reflected XSS in inline JavaScript event handlers, so the general XSS pattern is used.",
                  "The commit message references \u0027any logged-in victim,\u0027 implying authentication is required; the exact role or permission level of the victim is not specified."
                ],
                "capecRationale": [
                  {
                    "capecId": "CAPEC-1",
                    "rationale": "CAPEC-1 is the canonical CAPEC pattern for cross-site scripting attacks, covering reflected, stored, and DOM-based variants. The patch evidence shows a reflected XSS where URL-supplied data is injected into an inline JavaScript event handler. CAPEC-1 is the closest and most direct match. No more specific CAPEC sub-pattern for reflected XSS in inline JS handlers exists in the CAPEC catalog, so CAPEC-1 is the best available mapping."
                  }
                ],
                "commit": "95b8f21f6be9e20323dd101e7d085fc34765c7b7",
                "confidence": "high",
                "credits": [
                  {
                    "lang": "en",
                    "type": "reporter",
                    "value": "Jeroen Pinoy"
                  },
                  {
                    "lang": "en",
                    "type": "remediation developer",
                    "value": "iglocska"
                  },
                  {
                    "lang": "en",
                    "type": "remediation developer",
                    "value": "Claude Opus 4.8"
                  }
                ],
                "cvssRationale": "AV:N: The vulnerability is exploitable over the network via a crafted URL. AC:L: No race conditions or special environment conditions are required; the attacker simply crafts a URL with a malicious type value. AT:N: No manipulation of the attack target is needed. PR:N: The attacker requires no privileges on the MISP instance; the victim must be authenticated, but that is a precondition on the victim, not a privilege requirement on the attacker. UI:A: The victim must actively click a link or navigate to the attacker-supplied URL for the reflected payload to execute. VC:N, VI:N, VA:N: The MISP server itself is not directly compromised; the impact is confined to the victim\u0027s browser session. SC:L: The attacker can read session tokens or data visible in the MISP UI within the victim\u0027s browser. SI:L: The attacker can perform actions on behalf of the victim within the MISP application. SA:N: No availability impact on the victim\u0027s browser or the MISP server.",
                "fixSummary": "The fix replaces the unsafe raw PHP loop that concatenated type values into a JavaScript array literal with a call to json_encode() using the JSON_HEX_TAG, JSON_HEX_APOS, JSON_HEX_QUOT, and JSON_HEX_AMP flags. This ensures that all special characters (angle brackets, quotes, ampersands) in the type values are hex-encoded, preventing any value from breaking out of the JavaScript string/array context and injecting arbitrary script.",
                "generatedAt": "2026-09-22T12:45:39.951248Z",
                "generator": "patch2vuln.py",
                "model": "qwen3.8:27b",
                "modelComparison": {
                  "rankings": [
                    {
                      "agreementScore": 9,
                      "assumptionCount": 5,
                      "confidence": "high",
                      "model": "qwen3.8:27b",
                      "score": 6
                    }
                  ],
                  "selectedModel": "qwen3.8:27b",
                  "selectionMethod": "deterministic-consensus-v1",
                  "selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
                },
                "patchSha256": "33d14587239572ed6af4ca5d122f4b92405dbce1ff0317a1ff1e6e026073dc8c",
                "patchSummary": "In app/View/Elements/histogram.ctp, the onClick attribute previously built a JS array by iterating over $selectedTypes and echoing each value between double quotes with no escaping: [\u003c?php foreach ($selectedTypes as $t) echo \u0027\"\u0027 . $t . \u0027\", \u0027 ?\u003e]. The patch replaces this with a single json_encode($selectedTypes, JSON_HEX_TAG | JSON_HEX_APOS | JSON_HEX_QUOT | JSON_HEX_AMP) call, producing a safely encoded JSON array literal that cannot be broken out of by any element value.",
                "patchTruncated": false,
                "patches": [
                  {
                    "commit": "95b8f21f6be9e20323dd101e7d085fc34765c7b7",
                    "patchSha256": "33d14587239572ed6af4ca5d122f4b92405dbce1ff0317a1ff1e6e026073dc8c",
                    "source": "https://github.com/MISP/MISP/commit/95b8f21f6.patch",
                    "sourceUrl": "https://github.com/MISP/MISP/commit/95b8f21f6.patch",
                    "subject": "fix: [security] Escape the selected types in the attribute"
                  }
                ],
                "source": "https://github.com/MISP/MISP/commit/95b8f21f6.patch",
                "subject": "fix: [security] Escape the selected types in the attribute",
                "tagVersionBoundary": {
                  "commits_after_fix": 46,
                  "repository": "https://github.com/MISP/MISP",
                  "tag": "v2.5.47",
                  "version": "2.5.47",
                  "version_type": "semver"
                },
                "weaknessRationale": [
                  {
                    "cweId": "CWE-79",
                    "rationale": "The patch directly addresses the reflection of untrusted, URL-supplied data into a JavaScript context within an HTML attribute without encoding. This is a textbook reflected XSS (CWE-79). The specific sub-type is reflected XSS in a JavaScript context (inline event handler), but CWE-79 is the standard and most precise mapping."
                  }
                ]
              }
            }
          },
          "recordType": "advisory",
          "vulnId": "GCVE-1-2026-20161"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
    "assignerShortName": "CIRCL",
    "cveId": "CVE-2026-95661",
    "datePublished": "2026-09-22T12:54:46.496Z",
    "dateReserved": "2026-09-22T12:54:43.824Z",
    "dateUpdated": "2026-09-22T15:34:06.853Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

Mitigation MIT-4
Architecture and Design

Strategy: Libraries or Frameworks

  • Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482].
  • Examples of libraries and frameworks that make it easier to generate properly encoded output include Microsoft's Anti-XSS library, the OWASP ESAPI Encoding module, and Apache Wicket.
Mitigation
Implementation Architecture and Design
  • Understand the context in which your data will be used and the encoding that will be expected. This is especially important when transmitting data between different components, or when generating outputs that can contain multiple encodings at the same time, such as web pages or multi-part mail messages. Study all expected communication protocols and data representations to determine the required encoding strategies.
  • For any data that will be output to another web page, especially any data that was received from external inputs, use the appropriate encoding on all non-alphanumeric characters.
  • Parts of the same output document may require different encodings, which will vary depending on whether the output is in the:
  • etc. Note that HTML Entity Encoding is only appropriate for the HTML body.
  • Consult the XSS Prevention Cheat Sheet [REF-724] for more details on the types of encoding and escaping that are needed.
  • HTML body
  • Element attributes (such as src="XYZ")
  • URIs
  • JavaScript sections
  • Cascading Style Sheets and style property
Mitigation MIT-6
Architecture and Design Implementation

Strategy: Attack Surface Reduction

Understand all the potential areas where untrusted inputs can enter your software: parameters or arguments, cookies, anything read from the network, environment variables, reverse DNS lookups, query results, request headers, URL components, e-mail, files, filenames, databases, and any external systems that provide data to the application. Remember that such inputs may be obtained indirectly through API calls.

Mitigation MIT-15
Architecture and Design

For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-side checks entirely. Then, these modified values would be submitted to the server.

Mitigation MIT-27
Architecture and Design

Strategy: Parameterization

If available, use structured mechanisms that automatically enforce the separation between data and code. These mechanisms may be able to provide the relevant quoting, encoding, and validation automatically, instead of relying on the developer to provide this capability at every point where output is generated.

Mitigation MIT-30.1
Implementation

Strategy: Output Encoding

  • Use and specify an output encoding that can be handled by the downstream component that is reading the output. Common encodings include ISO-8859-1, UTF-7, and UTF-8. When an encoding is not specified, a downstream component may choose a different encoding, either by assuming a default encoding or automatically inferring which encoding is being used, which can be erroneous. When the encodings are inconsistent, the downstream component might treat some character or byte sequences as special, even if they are not special in the original encoding. Attackers might then be able to exploit this discrepancy and conduct injection attacks; they even might be able to bypass protection mechanisms that assume the original encoding is also being used by the downstream component.
  • The problem of inconsistent output encodings often arises in web pages. If an encoding is not specified in an HTTP header, web browsers often guess about which encoding is being used. This can open up the browser to subtle XSS attacks.
Mitigation MIT-43
Implementation

With Struts, write all data from form beans with the bean's filter attribute set to true.

Mitigation MIT-31
Implementation

Strategy: Attack Surface Reduction

To help mitigate XSS attacks against the user's session cookie, set the session cookie to be HttpOnly. In browsers that support the HttpOnly feature (such as more recent versions of Internet Explorer and Firefox), this attribute can prevent the user's session cookie from being accessible to malicious client-side scripts that use document.cookie. This is not a complete solution, since HttpOnly is not supported by all browsers. More importantly, XmlHttpRequest and other powerful browser technologies provide read access to HTTP headers, including the Set-Cookie header in which the HttpOnly flag is set.

Mitigation MIT-5
Implementation

Strategy: Input Validation

  • Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does.
  • When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules. As an example of business rule logic, "boat" may be syntactically valid because it only contains alphanumeric characters, but it is not valid if the input is only expected to contain colors such as "red" or "blue."
  • Do not rely exclusively on looking for malicious or malformed inputs. This is likely to miss at least one undesirable input, especially if the code's environment changes. This can give attackers enough room to bypass the intended validation. However, denylists can be useful for detecting potential attacks or determining which inputs are so malformed that they should be rejected outright.
  • When dynamically constructing web pages, use stringent allowlists that limit the character set based on the expected value of the parameter in the request. All input should be validated and cleansed, not just parameters that the user is supposed to specify, but all data in the request, including hidden fields, cookies, headers, the URL itself, and so forth. A common mistake that leads to continuing XSS vulnerabilities is to validate only fields that are expected to be redisplayed by the site. It is common to see data from the request that is reflected by the application server or the application that the development team did not anticipate. Also, a field that is not currently reflected may be used by a future developer. Therefore, validating ALL parts of the HTTP request is recommended.
  • Note that proper output encoding, escaping, and quoting is the most effective solution for preventing XSS, although input validation may provide some defense-in-depth. This is because it effectively limits what will appear in output. Input validation will not always prevent XSS, especially if you are required to support free-form text fields that could contain arbitrary characters. For example, in a chat application, the heart emoticon ("<3") would likely pass the validation step, since it is commonly used. However, it cannot be directly inserted into the web page because it contains the "<" character, which would need to be escaped or otherwise handled. In this case, stripping the "<" might reduce the risk of XSS, but it would produce incorrect behavior because the emoticon would not be recorded. This might seem to be a minor inconvenience, but it would be more important in a mathematical forum that wants to represent inequalities.
  • Even if you make a mistake in your validation (such as forgetting one out of 100 input fields), appropriate encoding is still likely to protect you from injection-based attacks. As long as it is not done in isolation, input validation is still a useful technique, since it may significantly reduce your attack surface, allow you to detect some attacks, and provide other security benefits that proper encoding does not address.
  • Ensure that you perform input validation at well-defined interfaces within the application. This will help protect the application even if a component is reused or moved elsewhere.
Mitigation MIT-21
Architecture and Design

Strategy: Enforcement by Conversion

When the set of acceptable objects, such as filenames or URLs, is limited or known, create a mapping from a set of fixed input values (such as numeric IDs) to the actual filenames or URLs, and reject all other inputs.

Mitigation MIT-29
Operation

Strategy: Firewall

Use an application firewall that can detect attacks against this weakness. It can be beneficial in cases in which the code cannot be fixed (because it is controlled by a third party), as an emergency prevention measure while more comprehensive software assurance measures are applied, or to provide defense in depth [REF-1481].

Mitigation MIT-16
Operation Implementation

Strategy: Environment Hardening

When using PHP, configure the application so that it does not use register_globals. During implementation, develop the application so that it does not rely on this feature, but be wary of implementing a register_globals emulation that is subject to weaknesses such as CWE-95, CWE-621, and similar issues.

CAPEC-209: XSS Using MIME Type Mismatch

An adversary creates a file with scripting content but where the specified MIME type of the file is such that scripting is not expected. The adversary tricks the victim into accessing a URL that responds with the script file. Some browsers will detect that the specified MIME type of the file does not match the actual type of its content and will automatically switch to using an interpreter for the real content type. If the browser does not invoke script filters before doing this, the adversary's script may run on the target unsanitized, possibly revealing the victim's cookies or executing arbitrary script in their browser.

CAPEC-588: DOM-Based XSS

This type of attack is a form of Cross-Site Scripting (XSS) where a malicious script is inserted into the client-side HTML being parsed by a web browser. Content served by a vulnerable web application includes script code used to manipulate the Document Object Model (DOM). This script code either does not properly validate input, or does not perform proper output encoding, thus creating an opportunity for an adversary to inject a malicious script launch a XSS attack. A key distinction between other XSS attacks and DOM-based attacks is that in other XSS attacks, the malicious script runs when the vulnerable web page is initially loaded, while a DOM-based attack executes sometime after the page loads. Another distinction of DOM-based attacks is that in some cases, the malicious script is never sent to the vulnerable web server at all. An attack like this is guaranteed to bypass any server-side filtering attempts to protect users.

CAPEC-591: Reflected XSS

This type of attack is a form of Cross-Site Scripting (XSS) where a malicious script is "reflected" off a vulnerable web application and then executed by a victim's browser. The process starts with an adversary delivering a malicious script to a victim and convincing the victim to send the script to the vulnerable web application.

CAPEC-592: Stored XSS

An adversary utilizes a form of Cross-site Scripting (XSS) where a malicious script is persistently "stored" within the data storage of a vulnerable web application as valid input.

CAPEC-63: Cross-Site Scripting (XSS)

An adversary embeds malicious scripts in content that will be served to web browsers. The goal of the attack is for the target software, the client-side browser, to execute the script with the users' privilege level. An attack of this type exploits a programs' vulnerabilities that are brought on by allowing remote hosts to execute code and scripts. Web browsers, for example, have some simple security controls in place, but if a remote attacker is allowed to execute scripts (through injecting them in to user-generated content like bulletin boards) then these controls may be bypassed. Further, these attacks are very difficult for an end user to detect.

CAPEC-85: AJAX Footprinting

This attack utilizes the frequent client-server roundtrips in Ajax conversation to scan a system. While Ajax does not open up new vulnerabilities per se, it does optimize them from an attacker point of view. A common first step for an attacker is to footprint the target environment to understand what attacks will work. Since footprinting relies on enumeration, the conversational pattern of rapid, multiple requests and responses that are typical in Ajax applications enable an attacker to look for many vulnerabilities, well-known ports, network locations and so on. The knowledge gained through Ajax fingerprinting can be used to support other attacks, such as XSS.