CWE-79
AllowedImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Abstraction: Base · Status: Stable
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
70975 vulnerabilities reference this CWE, most recent first.
CVE-2026-103389 (GCVE-0-2026-103389)
Vulnerability from cvelistv5 – Published: 2026-09-30 14:25 – Updated: 2026-09-30 15:28| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/8ea5783dd | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-30 14:24 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/8ea5783dd.patch
382869c811e8… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
8ea5783ddcfe
|
fix: [security] Galaxy icons are icon names, and the | 382869c811e8… |
Fix summary
The vulnerability is remediated by enforcing strict input validation on the galaxy icon field so that only valid Font Awesome icon names (lowercase alphanumeric characters and dashes) are accepted at write time. The sync/import capture path discards any icon value that does not conform. The correlation graph JSON generation falls back to a safe default icon for any previously stored invalid value. On the client side, both correlation graph scripts now set the icon as a CSS class attribute rather than injecting it as raw HTML, and apply an additional regex sanitization pass. The asset cache-busting version is incremented to ensure browsers load the corrected scripts.
Patch summary
Added a static isValidIconName() method and a regex constant (ICON_NAME_PATTERN) to the Galaxy model, plus a model-level validation rule restricting the icon field to lowercase letters, digits, and dashes. The captureGalaxy() method now blanks out any icon value that fails validation before persistence. CorrelationGraphTool::__createNode() now checks the icon against the validator and substitutes 'globe' for invalid stored values. Both correlation-graph.js and correlation-graphOvermind.js were changed from .html() string concatenation to .attr('class', ...) with a regex strip of non-conforming characters. AppController asset query version bumped from 225 to 226. A new PHPUnit test file (GalaxyIconNameTest.php) validates the icon name rule against known-good and known-bad payloads including the originally reported XSS vector.
CVSS rationale
AV:N: exploited over the network via the MISP web interface. AC:L: no race conditions or special timing; simply set the icon field and wait for a victim to view the graph. AT:N: no manipulation of the attack target required. PR:L: requires an authenticated user with perm_galaxy_editor, which is the default stock User role. UI:A: the victim must actively open the correlation graph of an event containing the affected galaxy cluster. VC/VI/VA:N: the server-side application is not directly compromised; the impact is on the victim's browser session. SC:H: script execution in the victim's session can read cookies, tokens, and sensitive page data. SI:H: the attacker can modify the victim's view, inject content, or trigger actions. SA:N: no availability impact on the system.
Weakness rationale
- CWE-79 The galaxy icon field was stored without validation and later rendered into the DOM via D3 .html(), allowing an attacker to inject and execute arbitrary script in the victim's browser. This is a textbook stored XSS.
- CWE-20 The root enabler is the absence of any server-side validation on the icon field at write time (add, edit, capture). The field accepted arbitrary strings including HTML markup, which was the precondition for the XSS.
Attack pattern rationale
- CAPEC-1 The attack pattern is a stored XSS: an authenticated user with galaxy editor permission injects a script payload into a persistent data field (galaxy icon), which is later rendered unsanitized in another user's browser via the correlation graph. CAPEC-1 is the closest and most direct match. No more specific CAPEC entry for stored XSS via a data field rendered by a graphing library exists in the CAPEC catalog, so CAPEC-1 is the best available mapping.
Assumptions to verify
- The affected version boundary is inferred from the tag_version_boundary metadata indicating the fix commit precedes v2.5.48 by 20 commits; no explicit 'fixed in' version is stated in the patch itself.
- The perm_galaxy_editor permission is assumed to be granted to the stock User role as stated in the commit message; the exact role-permission mapping was not independently verified from the patch.
- CAPEC-1 is the closest available mapping; no CAPEC entry specifically describes stored XSS via a graph-rendering library data field, so the general Cross Site Scripting pattern is used.
- CVSS UI:A assumes the victim must navigate to the correlation graph view of a specific event; if the graph is auto-loaded on a commonly visited page, UI could be lowered to Passive.
- The Co-Authored-By line references an AI assistant (Claude Fable 5.1); it is recorded as a tool credit rather than a human remediation developer.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 9 | high | 5 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103389",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:58:27.715153Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:28:06.728Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"Galaxy model",
"Correlation Graph (default theme)",
"Correlation Graph (Overmind theme)",
"Galaxy sync/import capture"
],
"product": "MISP",
"programFiles": [
"app/Model/Galaxy.php",
"app/Lib/Tools/CorrelationGraphTool.php",
"app/webroot/js/correlation-graph.js",
"app/webroot/js/correlation-graphOvermind.js"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Fable 5.1"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was persisted without any server-side validation through the galaxy add, edit, and sync/import capture endpoints. The stored value was subsequently concatenated directly into HTML markup by the D3-based correlation graph rendering scripts (both the default and Overmind themes) using the .html() method.\u003c/p\u003e\u003cp\u003eA user holding the perm_galaxy_editor permission, which is granted to the stock User role, could store arbitrary HTML or JavaScript in the icon field. Any other user who opened the correlation graph of an event containing a cluster belonging to that galaxy would have the injected script executed in their browser session.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Arbitrary script execution in the context of the victim\u0027s MISP session\u003c/p\u003e\u003cp\u003e- Potential theft of session credentials, manipulation of displayed data, or initiation of actions on behalf of the victim\u003c/p\u003e\u003cp\u003e- Affects both the default and Overmind UI themes\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt;2.5.48\u003c/p\u003e"
}
],
"value": "MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was persisted without any server-side validation through the galaxy add, edit, and sync/import capture endpoints. The stored value was subsequently concatenated directly into HTML markup by the D3-based correlation graph rendering scripts (both the default and Overmind themes) using the .html() method.\n\nA user holding the perm_galaxy_editor permission, which is granted to the stock User role, could store arbitrary HTML or JavaScript in the icon field. Any other user who opened the correlation graph of an event containing a cluster belonging to that galaxy would have the injected script executed in their browser session.\n\nImpact:\n\n- Arbitrary script execution in the context of the victim\u0027s MISP session\n\n- Potential theft of session credentials, manipulation of displayed data, or initiation of actions on behalf of the victim\n\n- Affects both the default and Overmind UI themes\n\nAffected versions: \u003c2.5.48"
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 Cross Site Scripting"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.2,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-20",
"description": "CWE-20 Improper Input Validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:25:59.230Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/8ea5783dd"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe vulnerability is remediated by enforcing strict input validation on the galaxy icon field so that only valid Font Awesome icon names (lowercase alphanumeric characters and dashes) are accepted at write time. The sync/import capture path discards any icon value that does not conform. The correlation graph JSON generation falls back to a safe default icon for any previously stored invalid value. On the client side, both correlation graph scripts now set the icon as a CSS class attribute rather than injecting it as raw HTML, and apply an additional regex sanitization pass. The asset cache-busting version is incremented to ensure browsers load the corrected scripts.\u003c/p\u003e"
}
],
"value": "The vulnerability is remediated by enforcing strict input validation on the galaxy icon field so that only valid Font Awesome icon names (lowercase alphanumeric characters and dashes) are accepted at write time. The sync/import capture path discards any icon value that does not conform. The correlation graph JSON generation falls back to a safe default icon for any previously stored invalid value. On the client side, both correlation graph scripts now set the icon as a CSS class attribute rather than injecting it as raw HTML, and apply an additional regex sanitization pass. The asset cache-busting version is incremented to ensure browsers load the corrected scripts."
}
],
"title": "MISP Stored Cross-Site Scripting via Unvalidated Galaxy Icon Field in Correlation Graph",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary is inferred from the tag_version_boundary metadata indicating the fix commit precedes v2.5.48 by 20 commits; no explicit \u0027fixed in\u0027 version is stated in the patch itself.",
"The perm_galaxy_editor permission is assumed to be granted to the stock User role as stated in the commit message; the exact role-permission mapping was not independently verified from the patch.",
"CAPEC-1 is the closest available mapping; no CAPEC entry specifically describes stored XSS via a graph-rendering library data field, so the general Cross Site Scripting pattern is used.",
"CVSS UI:A assumes the victim must navigate to the correlation graph view of a specific event; if the graph is auto-loaded on a commonly visited page, UI could be lowered to Passive.",
"The Co-Authored-By line references an AI assistant (Claude Fable 5.1); it is recorded as a tool credit rather than a human remediation developer."
],
"capecRationale": [
{
"capecId": "CAPEC-1",
"rationale": "The attack pattern is a stored XSS: an authenticated user with galaxy editor permission injects a script payload into a persistent data field (galaxy icon), which is later rendered unsanitized in another user\u0027s browser via the correlation graph. CAPEC-1 is the closest and most direct match. No more specific CAPEC entry for stored XSS via a data field rendered by a graphing library exists in the CAPEC catalog, so CAPEC-1 is the best available mapping."
}
],
"commit": "8ea5783ddcfe69be6013337a0d6732ac75a862e6",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Fable 5.1"
},
{
"lang": "en",
"type": "tool",
"value": "Claude Fable 5.1"
}
],
"cvssRationale": "AV:N: exploited over the network via the MISP web interface. AC:L: no race conditions or special timing; simply set the icon field and wait for a victim to view the graph. AT:N: no manipulation of the attack target required. PR:L: requires an authenticated user with perm_galaxy_editor, which is the default stock User role. UI:A: the victim must actively open the correlation graph of an event containing the affected galaxy cluster. VC/VI/VA:N: the server-side application is not directly compromised; the impact is on the victim\u0027s browser session. SC:H: script execution in the victim\u0027s session can read cookies, tokens, and sensitive page data. SI:H: the attacker can modify the victim\u0027s view, inject content, or trigger actions. SA:N: no availability impact on the system.",
"fixSummary": "The vulnerability is remediated by enforcing strict input validation on the galaxy icon field so that only valid Font Awesome icon names (lowercase alphanumeric characters and dashes) are accepted at write time. The sync/import capture path discards any icon value that does not conform. The correlation graph JSON generation falls back to a safe default icon for any previously stored invalid value. On the client side, both correlation graph scripts now set the icon as a CSS class attribute rather than injecting it as raw HTML, and apply an additional regex sanitization pass. The asset cache-busting version is incremented to ensure browsers load the corrected scripts.",
"generatedAt": "2026-09-30T14:24:01.890608Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "382869c811e8df5875a463c4b6275f754f4969445196f08d708cfee926528b0f",
"patchSummary": "Added a static isValidIconName() method and a regex constant (ICON_NAME_PATTERN) to the Galaxy model, plus a model-level validation rule restricting the icon field to lowercase letters, digits, and dashes. The captureGalaxy() method now blanks out any icon value that fails validation before persistence. CorrelationGraphTool::__createNode() now checks the icon against the validator and substitutes \u0027globe\u0027 for invalid stored values. Both correlation-graph.js and correlation-graphOvermind.js were changed from .html() string concatenation to .attr(\u0027class\u0027, ...) with a regex strip of non-conforming characters. AppController asset query version bumped from 225 to 226. A new PHPUnit test file (GalaxyIconNameTest.php) validates the icon name rule against known-good and known-bad payloads including the originally reported XSS vector.",
"patchTruncated": false,
"patches": [
{
"commit": "8ea5783ddcfe69be6013337a0d6732ac75a862e6",
"patchSha256": "382869c811e8df5875a463c4b6275f754f4969445196f08d708cfee926528b0f",
"source": "https://github.com/MISP/MISP/commit/8ea5783dd.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/8ea5783dd.patch",
"subject": "fix: [security] Galaxy icons are icon names, and the"
}
],
"source": "https://github.com/MISP/MISP/commit/8ea5783dd.patch",
"subject": "fix: [security] Galaxy icons are icon names, and the",
"tagVersionBoundary": {
"commits_after_fix": 20,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-79",
"rationale": "The galaxy icon field was stored without validation and later rendered into the DOM via D3 .html(), allowing an attacker to inject and execute arbitrary script in the victim\u0027s browser. This is a textbook stored XSS."
},
{
"cweId": "CWE-20",
"rationale": "The root enabler is the absence of any server-side validation on the icon field at write time (add, edit, capture). The field accepted arbitrary strings including HTML markup, which was the precondition for the XSS."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20142"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103389",
"datePublished": "2026-09-30T14:25:59.230Z",
"dateReserved": "2026-09-30T14:25:56.802Z",
"dateUpdated": "2026-09-30T15:28:06.728Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103388 (GCVE-0-2026-103388)
Vulnerability from cvelistv5 – Published: 2026-09-30 14:22 – Updated: 2026-09-30 15:28- CWE-79 - Improper Neutralization of Input in Web Page ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/118528767 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-30 14:12 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/118528767.patch
b68dbd672692… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
118528767735
|
fix: [security] Link a galaxy cluster source only when it is | b68dbd672692… |
Fix summary
The fix restricts the rendering of the Galaxy Cluster source field as a hyperlink to only http:// and https:// URLs by adding a regular-expression check (preg_match for ^https?://) in addition to the existing FILTER_VALIDATE_URL validation. This prevents javascript: and other non-HTTP URI schemes from being rendered as clickable links, eliminating the stored XSS vector. The change is applied consistently in both the default theme and the Overmind theme.
Patch summary
Two view templates are modified. In app/View/GalaxyClusters/view.ctp, the source value is extracted into a local variable and the conditional for rendering an anchor tag now requires both FILTER_VALIDATE_URL and a preg_match against /^https?:\/\//i. In app/View/Themed/Overmind/Elements/GalaxyClusters/View/galaxy_clusters_general.ctp, the same preg_match guard is added to the existing FILTER_VALIDATE_URL check. Net effect: only http(s) URLs produce a clickable link; all other values (including javascript:) are rendered as plain escaped text.
CVSS rationale
AV:N – MISP is a web application accessed over the network. AC:L – no race conditions or special environment needed; storing a javascript: URL is straightforward. AT:N – no manipulation of the attack target required. PR:L – attacker needs galaxy editor privileges (authenticated, non-admin role). UI:A – victim must click the malicious link for script execution. VC/VI/VA:N – the MISP server itself is not directly compromised; impact is on the victim's browser. SC:H – attacker can read cookies, session tokens, and manipulate the DOM in the victim's session. SI:H – attacker can perform actions on behalf of the victim within MISP. SA:N – no direct compromise of the application's security controls or system integrity.
Weakness rationale
- CWE-79 The application renders user-controlled data (the galaxy cluster source field) into an HTML anchor tag without restricting the URI scheme to safe values. Although output is HTML-escaped via h(), the href attribute still accepts javascript: URIs, resulting in stored XSS. CWE-79 is the narrowest defensible mapping.
Attack pattern rationale
- CAPEC-64 The attack pattern involves storing a malicious payload (a javascript: URL) in a persistent data field (galaxy cluster source) that is later rendered in a web page, executing script in the victim's browser upon interaction. This is a textbook persistent/stored XSS. CAPEC-64 is the closest and most precise match in the CAPEC catalog.
Assumptions to verify
- The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.48, 26 commits after fix); the exact first affected release is not stated in the patch.
- PR:L assumes galaxy editor privileges are a non-admin, role-based permission; the exact privilege model is not detailed in the patch.
- UI:A assumes the victim must actively click the rendered link; passive rendering without click does not execute the script.
- The CAPEC-64 mapping is the closest available pattern for stored XSS; no CAPEC specifically covers URI-scheme-based stored XSS, so CAPEC-64 is the best fit.
- The Co-Authored-By line references an AI assistant; it is credited as a tool rather than a human remediation developer.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 9 | high | 5 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103388",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:58:39.451751Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:28:06.980Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"GalaxyClusters view (default theme)",
"GalaxyClusters view (Overmind theme)"
],
"product": "MISP",
"programFiles": [
"app/View/GalaxyClusters/view.ctp",
"app/View/Themed/Overmind/Elements/GalaxyClusters/View/galaxy_clusters_general.ctp"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP renders the source field of a Galaxy Cluster as a clickable hyperlink whenever the stored value passes PHP\u0027s FILTER_VALIDATE_URL validation. Because FILTER_VALIDATE_URL accepts the javascript: URI scheme, a user with galaxy editor privileges on the local instance or on a synced instance could store a javascript: URL as the cluster source.\u003c/p\u003e\u003cp\u003eWhen another user views the affected Galaxy Cluster and clicks the rendered link, the embedded script executes in the victim\u0027s browser context, enabling session hijacking, data exfiltration, or actions performed on behalf of the victim.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- Attacker must hold galaxy editor privileges (local or via sync).\u003c/p\u003e\u003cp\u003e- Victim must view the affected cluster and click the malicious link.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Stored cross-site scripting (XSS) in the victim\u0027s browser.\u003c/p\u003e\u003cp\u003e- Potential session theft, credential harvesting, or unauthorized actions within the MISP application.\u003c/p\u003e\u003cp\u003eAffected: \u0026lt;2.5.48.\u003c/p\u003e"
}
],
"value": "MISP renders the source field of a Galaxy Cluster as a clickable hyperlink whenever the stored value passes PHP\u0027s FILTER_VALIDATE_URL validation. Because FILTER_VALIDATE_URL accepts the javascript: URI scheme, a user with galaxy editor privileges on the local instance or on a synced instance could store a javascript: URL as the cluster source.\n\nWhen another user views the affected Galaxy Cluster and clicks the rendered link, the embedded script executes in the victim\u0027s browser context, enabling session hijacking, data exfiltration, or actions performed on behalf of the victim.\n\nPreconditions:\n\n- Attacker must hold galaxy editor privileges (local or via sync).\n\n- Victim must view the affected cluster and click the malicious link.\n\nImpact:\n\n- Stored cross-site scripting (XSS) in the victim\u0027s browser.\n\n- Potential session theft, credential harvesting, or unauthorized actions within the MISP application.\n\nAffected: \u003c2.5.48."
}
],
"impacts": [
{
"capecId": "CAPEC-64",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-64 XSS - Persistent"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.2,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input in Web Page (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:22:36.271Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/118528767"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix restricts the rendering of the Galaxy Cluster source field as a hyperlink to only http:// and https:// URLs by adding a regular-expression check (preg_match for ^https?://) in addition to the existing FILTER_VALIDATE_URL validation. This prevents javascript: and other non-HTTP URI schemes from being rendered as clickable links, eliminating the stored XSS vector. The change is applied consistently in both the default theme and the Overmind theme.\u003c/p\u003e"
}
],
"value": "The fix restricts the rendering of the Galaxy Cluster source field as a hyperlink to only http:// and https:// URLs by adding a regular-expression check (preg_match for ^https?://) in addition to the existing FILTER_VALIDATE_URL validation. This prevents javascript: and other non-HTTP URI schemes from being rendered as clickable links, eliminating the stored XSS vector. The change is applied consistently in both the default theme and the Overmind theme."
}
],
"title": "MISP Stored Cross-Site Scripting via JavaScript URL in Galaxy Cluster Source Field",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.48, 26 commits after fix); the exact first affected release is not stated in the patch.",
"PR:L assumes galaxy editor privileges are a non-admin, role-based permission; the exact privilege model is not detailed in the patch.",
"UI:A assumes the victim must actively click the rendered link; passive rendering without click does not execute the script.",
"The CAPEC-64 mapping is the closest available pattern for stored XSS; no CAPEC specifically covers URI-scheme-based stored XSS, so CAPEC-64 is the best fit.",
"The Co-Authored-By line references an AI assistant; it is credited as a tool rather than a human remediation developer."
],
"capecRationale": [
{
"capecId": "CAPEC-64",
"rationale": "The attack pattern involves storing a malicious payload (a javascript: URL) in a persistent data field (galaxy cluster source) that is later rendered in a web page, executing script in the victim\u0027s browser upon interaction. This is a textbook persistent/stored XSS. CAPEC-64 is the closest and most precise match in the CAPEC catalog."
}
],
"commit": "11852876773554d79ff57937a235d18a1e4473dc",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"cvssRationale": "AV:N \u2013 MISP is a web application accessed over the network. AC:L \u2013 no race conditions or special environment needed; storing a javascript: URL is straightforward. AT:N \u2013 no manipulation of the attack target required. PR:L \u2013 attacker needs galaxy editor privileges (authenticated, non-admin role). UI:A \u2013 victim must click the malicious link for script execution. VC/VI/VA:N \u2013 the MISP server itself is not directly compromised; impact is on the victim\u0027s browser. SC:H \u2013 attacker can read cookies, session tokens, and manipulate the DOM in the victim\u0027s session. SI:H \u2013 attacker can perform actions on behalf of the victim within MISP. SA:N \u2013 no direct compromise of the application\u0027s security controls or system integrity.",
"fixSummary": "The fix restricts the rendering of the Galaxy Cluster source field as a hyperlink to only http:// and https:// URLs by adding a regular-expression check (preg_match for ^https?://) in addition to the existing FILTER_VALIDATE_URL validation. This prevents javascript: and other non-HTTP URI schemes from being rendered as clickable links, eliminating the stored XSS vector. The change is applied consistently in both the default theme and the Overmind theme.",
"generatedAt": "2026-09-30T14:12:32.112077Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "b68dbd6726929ff1680daeae2a273fc346e7075d7ded36195994315c19ccf278",
"patchSummary": "Two view templates are modified. In app/View/GalaxyClusters/view.ctp, the source value is extracted into a local variable and the conditional for rendering an anchor tag now requires both FILTER_VALIDATE_URL and a preg_match against /^https?:\\/\\//i. In app/View/Themed/Overmind/Elements/GalaxyClusters/View/galaxy_clusters_general.ctp, the same preg_match guard is added to the existing FILTER_VALIDATE_URL check. Net effect: only http(s) URLs produce a clickable link; all other values (including javascript:) are rendered as plain escaped text.",
"patchTruncated": false,
"patches": [
{
"commit": "11852876773554d79ff57937a235d18a1e4473dc",
"patchSha256": "b68dbd6726929ff1680daeae2a273fc346e7075d7ded36195994315c19ccf278",
"source": "https://github.com/MISP/MISP/commit/118528767.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/118528767.patch",
"subject": "fix: [security] Link a galaxy cluster source only when it is"
}
],
"source": "https://github.com/MISP/MISP/commit/118528767.patch",
"subject": "fix: [security] Link a galaxy cluster source only when it is",
"tagVersionBoundary": {
"commits_after_fix": 26,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-79",
"rationale": "The application renders user-controlled data (the galaxy cluster source field) into an HTML anchor tag without restricting the URI scheme to safe values. Although output is HTML-escaped via h(), the href attribute still accepts javascript: URIs, resulting in stored XSS. CWE-79 is the narrowest defensible mapping."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20256"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103388",
"datePublished": "2026-09-30T14:22:36.271Z",
"dateReserved": "2026-09-30T14:22:32.098Z",
"dateUpdated": "2026-09-30T15:28:06.980Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103354 (GCVE-0-2026-103354)
Vulnerability from cvelistv5 – Published: 2026-10-04 07:00 – Updated: 2026-10-04 07:00 X_Open Source- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://patchstack.com/database/wordpress/plugin/… | vdb-entry |
| Vendor | Product | Version | |
|---|---|---|---|
| Liquid Web / StellarWP | Gutenberg Blocks by Kadence Blocks |
Affected:
0 , ≤ 3.7.11.1
(custom)
|
{
"containers": {
"cna": {
"affected": [
{
"collectionURL": "https://wordpress.org/plugins",
"defaultStatus": "unaffected",
"packageName": "kadence-blocks",
"product": "Gutenberg Blocks by Kadence Blocks",
"vendor": "Liquid Web / StellarWP",
"versions": [
{
"changes": [
{
"at": "3.7.12",
"status": "unaffected"
}
],
"lessThanOrEqual": "3.7.11.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "vta.itsec | Patchstack Bug Bounty Program"
}
],
"datePublic": "2026-10-02T06:39:03.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027) vulnerability in Liquid Web / StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks allows Stored XSS.\u003cp\u003eThis issue affects Gutenberg Blocks by Kadence Blocks: from n/a through 3.7.11.1.\u003c/p\u003e"
}
],
"value": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027) vulnerability in Liquid Web / StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks allows Stored XSS.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through 3.7.11.1."
}
],
"impacts": [
{
"capecId": "CAPEC-592",
"descriptions": [
{
"lang": "en",
"value": "Stored XSS"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-04T07:00:42.870Z",
"orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"shortName": "Patchstack"
},
"references": [
{
"tags": [
"vdb-entry"
],
"url": "https://patchstack.com/database/wordpress/plugin/kadence-blocks/vulnerability/wordpress-gutenberg-blocks-by-kadence-blocks-plugin-3-7-11-1-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Update the WordPress Gutenberg Blocks by Kadence Blocks plugin to the latest available version (at least 3.7.12)."
}
],
"value": "Update the WordPress Gutenberg Blocks by Kadence Blocks plugin to the latest available version (at least 3.7.12)."
}
],
"tags": [
"x_open-source"
],
"title": "WordPress Gutenberg Blocks by Kadence Blocks plugin \u003c= 3.7.11.1 - Cross Site Scripting (XSS) vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"assignerShortName": "Patchstack",
"cveId": "CVE-2026-103354",
"datePublished": "2026-10-04T07:00:42.870Z",
"dateReserved": "2026-09-30T12:43:33.094Z",
"dateUpdated": "2026-10-04T07:00:42.870Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103344 (GCVE-0-2026-103344)
Vulnerability from cvelistv5 – Published: 2026-10-04 08:00 – Updated: 2026-10-04 08:00 X_Open Source- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://patchstack.com/database/wordpress/plugin/… | vdb-entry |
| Vendor | Product | Version | |
|---|---|---|---|
| Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) |
Affected:
0 , ≤ 2.0.20
(custom)
|
{
"containers": {
"cna": {
"affected": [
{
"collectionURL": "https://wordpress.org/plugins",
"defaultStatus": "unaffected",
"packageName": "unlimited-elements-for-elementor",
"product": "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)",
"vendor": "Unlimited Elements",
"versions": [
{
"changes": [
{
"at": "2.0.21",
"status": "unaffected"
}
],
"lessThanOrEqual": "2.0.20",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "nh4tvd | Patchstack Bug Bounty Program"
}
],
"datePublic": "2026-10-02T07:16:56.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027) vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.\u003cp\u003eThis issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.\u003c/p\u003e"
}
],
"value": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027) vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20."
}
],
"impacts": [
{
"capecId": "CAPEC-591",
"descriptions": [
{
"lang": "en",
"value": "Reflected XSS"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-04T08:00:09.427Z",
"orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"shortName": "Patchstack"
},
"references": [
{
"tags": [
"vdb-entry"
],
"url": "https://patchstack.com/database/wordpress/plugin/unlimited-elements-for-elementor/vulnerability/wordpress-unlimited-elements-for-elementor-free-widgets-addons-templates-plugin-2-0-20-cross-site-scripting-xss-vulnerability-2?_s_id=cve"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Update the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin to the latest available version (at least 2.0.21)."
}
],
"value": "Update the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin to the latest available version (at least 2.0.21)."
}
],
"tags": [
"x_open-source"
],
"title": "WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin \u003c= 2.0.20 - Cross Site Scripting (XSS) vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"assignerShortName": "Patchstack",
"cveId": "CVE-2026-103344",
"datePublished": "2026-10-04T08:00:09.427Z",
"dateReserved": "2026-09-30T12:43:33.093Z",
"dateUpdated": "2026-10-04T08:00:09.427Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103343 (GCVE-0-2026-103343)
Vulnerability from cvelistv5 – Published: 2026-10-01 12:27 – Updated: 2026-10-01 13:18 X_Open Source- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://patchstack.com/database/wordpress/plugin/… | vdb-entry |
| Vendor | Product | Version | |
|---|---|---|---|
| WP ManageNinja LLC | FluentForm |
Affected:
0 , ≤ 6.2.14
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103343",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T13:18:47.930910Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T13:18:56.897Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://wordpress.org/plugins",
"defaultStatus": "unaffected",
"packageName": "fluentform",
"product": "FluentForm",
"vendor": "WP ManageNinja LLC",
"versions": [
{
"changes": [
{
"at": "6.2.15",
"status": "unaffected"
}
],
"lessThanOrEqual": "6.2.14",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Intrudify | Patchstack Bug Bounty Program"
}
],
"datePublic": "2026-10-01T12:27:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027) vulnerability in WP ManageNinja LLC FluentForm fluentform allows Stored XSS.\u003cp\u003eThis issue affects FluentForm: from n/a through 6.2.14.\u003c/p\u003e"
}
],
"value": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027) vulnerability in WP ManageNinja LLC FluentForm fluentform allows Stored XSS.This issue affects FluentForm: from n/a through 6.2.14."
}
],
"impacts": [
{
"capecId": "CAPEC-592",
"descriptions": [
{
"lang": "en",
"value": "Stored XSS"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T12:27:40.996Z",
"orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"shortName": "Patchstack"
},
"references": [
{
"tags": [
"vdb-entry"
],
"url": "https://patchstack.com/database/wordpress/plugin/fluentform/vulnerability/wordpress-fluentform-plugin-6-2-14-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Update the WordPress FluentForm plugin to the latest available version (at least 6.2.15)."
}
],
"value": "Update the WordPress FluentForm plugin to the latest available version (at least 6.2.15)."
}
],
"tags": [
"x_open-source"
],
"title": "WordPress FluentForm plugin \u003c= 6.2.14 - Cross Site Scripting (XSS) vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"assignerShortName": "Patchstack",
"cveId": "CVE-2026-103343",
"datePublished": "2026-10-01T12:27:40.996Z",
"dateReserved": "2026-09-30T12:43:33.093Z",
"dateUpdated": "2026-10-01T13:18:56.897Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103342 (GCVE-0-2026-103342)
Vulnerability from cvelistv5 – Published: 2026-10-03 14:00 – Updated: 2026-10-03 15:12 X_Open Source- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://patchstack.com/database/wordpress/plugin/… | vdb-entry |
| Vendor | Product | Version | |
|---|---|---|---|
| Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) |
Affected:
0 , ≤ 2.0.20
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103342",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-03T15:09:54.625208Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T15:12:23.526Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://wordpress.org/plugins",
"defaultStatus": "unaffected",
"packageName": "unlimited-elements-for-elementor",
"product": "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)",
"vendor": "Unlimited Elements",
"versions": [
{
"changes": [
{
"at": "2.0.21",
"status": "unaffected"
}
],
"lessThanOrEqual": "2.0.20",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "nh4tvd | Patchstack Bug Bounty Program"
}
],
"datePublic": "2026-10-01T13:58:58.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027) vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.\u003cp\u003eThis issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.\u003c/p\u003e"
}
],
"value": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027) vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20."
}
],
"impacts": [
{
"capecId": "CAPEC-591",
"descriptions": [
{
"lang": "en",
"value": "Reflected XSS"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T14:00:11.382Z",
"orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"shortName": "Patchstack"
},
"references": [
{
"tags": [
"vdb-entry"
],
"url": "https://patchstack.com/database/wordpress/plugin/unlimited-elements-for-elementor/vulnerability/wordpress-unlimited-elements-for-elementor-free-widgets-addons-templates-plugin-2-0-20-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Update the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin to the latest available version (at least 2.0.21)."
}
],
"value": "Update the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin to the latest available version (at least 2.0.21)."
}
],
"tags": [
"x_open-source"
],
"title": "WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin \u003c= 2.0.20 - Cross Site Scripting (XSS) vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"assignerShortName": "Patchstack",
"cveId": "CVE-2026-103342",
"datePublished": "2026-10-03T14:00:11.382Z",
"dateReserved": "2026-09-30T12:43:33.093Z",
"dateUpdated": "2026-10-03T15:12:23.526Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103339 (GCVE-0-2026-103339)
Vulnerability from cvelistv5 – Published: 2026-10-01 12:34 – Updated: 2026-10-01 13:12 X_Open Source- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://patchstack.com/database/wordpress/plugin/… | vdb-entry |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103339",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T13:11:39.506878Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T13:12:11.502Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://wordpress.org/plugins",
"defaultStatus": "unaffected",
"packageName": "metform",
"product": "Metform",
"vendor": "Wpmet",
"versions": [
{
"changes": [
{
"at": "4.3.1",
"status": "unaffected"
}
],
"lessThanOrEqual": "4.3.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Intrudify | Patchstack Bug Bounty Program"
}
],
"datePublic": "2026-10-01T12:34:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027) vulnerability in Wpmet Metform metform allows Stored XSS.\u003cp\u003eThis issue affects Metform: from n/a through 4.3.0.\u003c/p\u003e"
}
],
"value": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027) vulnerability in Wpmet Metform metform allows Stored XSS.This issue affects Metform: from n/a through 4.3.0."
}
],
"impacts": [
{
"capecId": "CAPEC-592",
"descriptions": [
{
"lang": "en",
"value": "Stored XSS"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T12:35:03.529Z",
"orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"shortName": "Patchstack"
},
"references": [
{
"tags": [
"vdb-entry"
],
"url": "https://patchstack.com/database/wordpress/plugin/metform/vulnerability/wordpress-metform-plugin-4-3-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Update the WordPress Metform plugin to the latest available version (at least 4.3.1)."
}
],
"value": "Update the WordPress Metform plugin to the latest available version (at least 4.3.1)."
}
],
"tags": [
"x_open-source"
],
"title": "WordPress Metform plugin \u003c= 4.3.0 - Cross Site Scripting (XSS) vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"assignerShortName": "Patchstack",
"cveId": "CVE-2026-103339",
"datePublished": "2026-10-01T12:34:57.157Z",
"dateReserved": "2026-09-30T12:43:33.093Z",
"dateUpdated": "2026-10-01T13:12:11.502Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103321 (GCVE-0-2026-103321)
Vulnerability from cvelistv5 – Published: 2026-09-30 12:19 – Updated: 2026-09-30 12:44| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/92c7ccc43 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-30 11:21 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/92c7ccc43.patch
0ecb893de300… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
92c7ccc4398a
|
fix: [security] Validate the event graph preview and stop | 0ecb893de300… |
Fix summary
The vulnerability is remediated by enforcing strict server-side validation of the preview image field, restricting it to a well-formed base64-encoded PNG data URL, and by replacing the client-side string-concatenation rendering with DOM-based attribute assignment that does not interpret the value as HTML.
Patch summary
In app/Model/EventGraph.php, a new validation rule is added for the preview_img field requiring it to match the regex /^data:image\/png;base64,[A-Za-z0-9+\/]*={0,2}$/ (allowing empty). In app/webroot/js/event-graph.js, two occurrences of string-concatenated img tag construction (return '<img ... src="' + value + '" />') are replaced with jQuery DOM construction using $('<img ...>').prop('src', value), which sets the attribute safely without HTML parsing.
CVSS rationale
AV:N: exploited over the network via the MISP web interface. AC:L: no race conditions or special conditions required; storing a crafted value and viewing the graph is straightforward. AT:N: no manipulation of the attack target needed. PR:L: attacker needs a low-privilege authenticated MISP account to create/modify an event graph. UI:P: the victim passively triggers the XSS by viewing the event graph preview (hovering a button), a normal workflow action. VC/VI/VA:N: the MISP server itself is not compromised; the impact is in the victim's browser. SC:H: the attacker can read cookies, tokens, and data in the victim's session. SI:H: the attacker can perform authenticated actions as the victim. SA:N: no availability impact on the victim's system.
Weakness rationale
- CWE-79 The stored preview_img value was rendered into an HTML attribute via string concatenation without sufficient neutralization, enabling script injection in the victim's browser. This is a textbook stored XSS.
- CWE-20 The server accepted and persisted the preview_img field without any format validation, allowing arbitrary content to be stored and later rendered. The fix adds a strict regex validation rule.
Attack pattern rationale
- CAPEC-1 The patch directly addresses a stored XSS where attacker-controlled data is rendered into a web page without proper encoding or validation. CAPEC-1 is the canonical attack pattern for XSS and is the closest match. No uncertainty in this mapping; the commit message explicitly identifies the issue as stored XSS.
Assumptions to verify
- The affected version range is inferred from the tag_version_boundary (v2.5.48 with 43 commits after the fix); the exact fixed release version is not stated in the patch metadata.
- PR:L assumes the attacker needs at least a basic authenticated MISP account to create or modify an event graph entry; the patch does not specify the exact permission level required.
- UI:P assumes the victim triggers the XSS by viewing the event graph preview as part of normal workflow (hovering the plot button), which is a passive interaction rather than an active click on a crafted link.
- The CAPEC-1 mapping is direct and unambiguous given the explicit stored XSS identification in the commit message.
- The Co-Authored-By line referencing Claude Opus 4.8 is treated as a tool credit per the commit metadata; it is not a human contributor.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 9 | high | 5 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103321",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T12:44:13.205587Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T12:44:22.064Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"EventGraph model",
"event-graph.js client-side rendering"
],
"product": "MISP",
"programFiles": [
"app/Model/EventGraph.php",
"app/webroot/js/event-graph.js"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Bastien Bossiroy of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature.\u003c/p\u003e\u003cp\u003eThe event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element\u0027s src attribute via string concatenation, allowing a crafted value to break out of the attribute context and inject arbitrary script.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- An authenticated MISP user with the ability to create or modify an event graph entry.\u003c/p\u003e\u003cp\u003e- A second user (the victim) who views the event graph and triggers the preview popover.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Execution of arbitrary JavaScript in the victim\u0027s browser within the MISP application context.\u003c/p\u003e\u003cp\u003e- Potential theft of session tokens, cookies, or sensitive data accessible to the victim\u0027s browser.\u003c/p\u003e\u003cp\u003e- Potential for performing actions on behalf of the victim within the MISP application.\u003c/p\u003e\u003cp\u003eAffected: MISP versions prior to the fix (commit applied after v2.5.48).\u003c/p\u003e"
}
],
"value": "MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature.\n\nThe event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element\u0027s src attribute via string concatenation, allowing a crafted value to break out of the attribute context and inject arbitrary script.\n\nPreconditions:\n\n- An authenticated MISP user with the ability to create or modify an event graph entry.\n\n- A second user (the victim) who views the event graph and triggers the preview popover.\n\nImpact:\n\n- Execution of arbitrary JavaScript in the victim\u0027s browser within the MISP application context.\n\n- Potential theft of session tokens, cookies, or sensitive data accessible to the victim\u0027s browser.\n\n- Potential for performing actions on behalf of the victim within the MISP application.\n\nAffected: MISP versions prior to the fix (commit applied after v2.5.48)."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 Cross Site Scripting (XSS)"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.3,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-20",
"description": "CWE-20 Improper Input Validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T12:19:01.829Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/92c7ccc43"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe vulnerability is remediated by enforcing strict server-side validation of the preview image field, restricting it to a well-formed base64-encoded PNG data URL, and by replacing the client-side string-concatenation rendering with DOM-based attribute assignment that does not interpret the value as HTML.\u003c/p\u003e"
}
],
"value": "The vulnerability is remediated by enforcing strict server-side validation of the preview image field, restricting it to a well-formed base64-encoded PNG data URL, and by replacing the client-side string-concatenation rendering with DOM-based attribute assignment that does not interpret the value as HTML."
}
],
"title": "MISP Stored Cross-Site Scripting (XSS) via Unvalidated Event Graph Preview Image",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version range is inferred from the tag_version_boundary (v2.5.48 with 43 commits after the fix); the exact fixed release version is not stated in the patch metadata.",
"PR:L assumes the attacker needs at least a basic authenticated MISP account to create or modify an event graph entry; the patch does not specify the exact permission level required.",
"UI:P assumes the victim triggers the XSS by viewing the event graph preview as part of normal workflow (hovering the plot button), which is a passive interaction rather than an active click on a crafted link.",
"The CAPEC-1 mapping is direct and unambiguous given the explicit stored XSS identification in the commit message.",
"The Co-Authored-By line referencing Claude Opus 4.8 is treated as a tool credit per the commit metadata; it is not a human contributor."
],
"capecRationale": [
{
"capecId": "CAPEC-1",
"rationale": "The patch directly addresses a stored XSS where attacker-controlled data is rendered into a web page without proper encoding or validation. CAPEC-1 is the canonical attack pattern for XSS and is the closest match. No uncertainty in this mapping; the commit message explicitly identifies the issue as stored XSS."
}
],
"commit": "92c7ccc4398a64e61699bd79fb4010703616fc59",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Bastien Bossiroy of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
}
],
"cvssRationale": "AV:N: exploited over the network via the MISP web interface. AC:L: no race conditions or special conditions required; storing a crafted value and viewing the graph is straightforward. AT:N: no manipulation of the attack target needed. PR:L: attacker needs a low-privilege authenticated MISP account to create/modify an event graph. UI:P: the victim passively triggers the XSS by viewing the event graph preview (hovering a button), a normal workflow action. VC/VI/VA:N: the MISP server itself is not compromised; the impact is in the victim\u0027s browser. SC:H: the attacker can read cookies, tokens, and data in the victim\u0027s session. SI:H: the attacker can perform authenticated actions as the victim. SA:N: no availability impact on the victim\u0027s system.",
"fixSummary": "The vulnerability is remediated by enforcing strict server-side validation of the preview image field, restricting it to a well-formed base64-encoded PNG data URL, and by replacing the client-side string-concatenation rendering with DOM-based attribute assignment that does not interpret the value as HTML.",
"generatedAt": "2026-09-30T11:21:27.655462Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "0ecb893de30056bc3f9609fcb8de43d60b1cedd6a1eea7d6aa53ef6d351d642a",
"patchSummary": "In app/Model/EventGraph.php, a new validation rule is added for the preview_img field requiring it to match the regex /^data:image\\/png;base64,[A-Za-z0-9+\\/]*={0,2}$/ (allowing empty). In app/webroot/js/event-graph.js, two occurrences of string-concatenated img tag construction (return \u0027\u003cimg ... src=\"\u0027 + value + \u0027\" /\u003e\u0027) are replaced with jQuery DOM construction using $(\u0027\u003cimg ...\u003e\u0027).prop(\u0027src\u0027, value), which sets the attribute safely without HTML parsing.",
"patchTruncated": false,
"patches": [
{
"commit": "92c7ccc4398a64e61699bd79fb4010703616fc59",
"patchSha256": "0ecb893de30056bc3f9609fcb8de43d60b1cedd6a1eea7d6aa53ef6d351d642a",
"source": "https://github.com/MISP/MISP/commit/92c7ccc43.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/92c7ccc43.patch",
"subject": "fix: [security] Validate the event graph preview and stop"
}
],
"source": "https://github.com/MISP/MISP/commit/92c7ccc43.patch",
"subject": "fix: [security] Validate the event graph preview and stop",
"tagVersionBoundary": {
"commits_after_fix": 43,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-79",
"rationale": "The stored preview_img value was rendered into an HTML attribute via string concatenation without sufficient neutralization, enabling script injection in the victim\u0027s browser. This is a textbook stored XSS."
},
{
"cweId": "CWE-20",
"rationale": "The server accepted and persisted the preview_img field without any format validation, allowing arbitrary content to be stored and later rendered. The fix adds a strict regex validation rule."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20294"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103321",
"datePublished": "2026-09-30T12:19:01.829Z",
"dateReserved": "2026-09-30T12:18:54.232Z",
"dateUpdated": "2026-09-30T12:44:22.064Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103292 (GCVE-0-2026-103292)
Vulnerability from cvelistv5 – Published: 2026-10-01 10:42 – Updated: 2026-10-01 13:04- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://github.com/TryGhost/Ghost/security/adviso… | vendor-advisory |
| https://www.vulncheck.com/advisories/ghost-0.5.3-… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103292",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T12:56:49.408634Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T13:04:08.126Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/ghost",
"product": "Ghost",
"vendor": "TryGhost",
"versions": [
{
"lessThan": "6.50.0",
"status": "affected",
"version": "0.5.3",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.50.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.50.0",
"versionStartIncluding": "0.5.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "kah-ja"
}
],
"datePublic": "2026-09-08T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Ghost versions from 0.5.3 through versions prior to 6.50.0 fail to sanitize the data placed in the JSON-LD HTML tag emitted by the {{ghost_head}} helper. An authenticated user with limited privileges can inject unescaped content that is rendered as script in the published page, potentially leading to compromise of a staff user\u0027s admin session when that user views the affected page."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T10:42:25.235Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-mp9q-4q6m-44f5)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/TryGhost/Ghost/security/advisories/GHSA-mp9q-4q6m-44f5"
},
{
"name": "VulnCheck Advisory: Ghost 0.5.3 before 6.50.0 Cross-Site Scripting via ghost_head",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/ghost-0.5.3-before-6.50.0-cross-site-scripting-via-ghost-head"
}
],
"title": "Ghost 0.5.3 before 6.50.0 Cross-Site Scripting via ghost_head",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-103292",
"datePublished": "2026-10-01T10:42:25.235Z",
"dateReserved": "2026-09-30T10:59:26.443Z",
"dateUpdated": "2026-10-01T13:04:08.126Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103277 (GCVE-0-2026-103277)
Vulnerability from cvelistv5 – Published: 2026-10-01 10:42 – Updated: 2026-10-01 13:35- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://github.com/TryGhost/Ghost/security/adviso… | vendor-advisory |
| https://www.vulncheck.com/advisories/ghost-2.5.0-… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103277",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T13:34:51.106508Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T13:35:02.155Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/ghost",
"product": "Ghost",
"vendor": "TryGhost",
"versions": [
{
"lessThan": "6.34.0",
"status": "affected",
"version": "2.5.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.34.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.34.0",
"versionStartIncluding": "2.5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"datePublic": "2026-08-13T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution vulnerability in the oEmbed preview feature that fails to sandbox externally hosted scripts. Attackers can craft malicious oEmbed content to execute scripts in the context of a staff user\u0027s admin session, potentially compromising administrative access."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T10:42:14.602Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-8vhf-xxpj-4qrg)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/TryGhost/Ghost/security/advisories/GHSA-8vhf-xxpj-4qrg"
},
{
"name": "VulnCheck Advisory: Ghost 2.5.0 before 6.34.0 Untrusted Script Execution via oEmbed",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/ghost-2.5.0-before-6.34.0-untrusted-script-execution-via-oembed"
}
],
"title": "Ghost 2.5.0 before 6.34.0 Untrusted Script Execution via oEmbed",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-103277",
"datePublished": "2026-10-01T10:42:14.602Z",
"dateReserved": "2026-09-30T10:59:00.638Z",
"dateUpdated": "2026-10-01T13:35:02.155Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Mitigation MIT-4
Strategy: Libraries or Frameworks
- Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482].
- Examples of libraries and frameworks that make it easier to generate properly encoded output include Microsoft's Anti-XSS library, the OWASP ESAPI Encoding module, and Apache Wicket.
Mitigation
- Understand the context in which your data will be used and the encoding that will be expected. This is especially important when transmitting data between different components, or when generating outputs that can contain multiple encodings at the same time, such as web pages or multi-part mail messages. Study all expected communication protocols and data representations to determine the required encoding strategies.
- For any data that will be output to another web page, especially any data that was received from external inputs, use the appropriate encoding on all non-alphanumeric characters.
- Parts of the same output document may require different encodings, which will vary depending on whether the output is in the:
- etc. Note that HTML Entity Encoding is only appropriate for the HTML body.
- Consult the XSS Prevention Cheat Sheet [REF-724] for more details on the types of encoding and escaping that are needed.
- HTML body
- Element attributes (such as src="XYZ")
- URIs
- JavaScript sections
- Cascading Style Sheets and style property
Mitigation MIT-6
Strategy: Attack Surface Reduction
Understand all the potential areas where untrusted inputs can enter your software: parameters or arguments, cookies, anything read from the network, environment variables, reverse DNS lookups, query results, request headers, URL components, e-mail, files, filenames, databases, and any external systems that provide data to the application. Remember that such inputs may be obtained indirectly through API calls.
Mitigation MIT-15
For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-side checks entirely. Then, these modified values would be submitted to the server.
Mitigation MIT-27
Strategy: Parameterization
If available, use structured mechanisms that automatically enforce the separation between data and code. These mechanisms may be able to provide the relevant quoting, encoding, and validation automatically, instead of relying on the developer to provide this capability at every point where output is generated.
Mitigation MIT-30.1
Strategy: Output Encoding
- Use and specify an output encoding that can be handled by the downstream component that is reading the output. Common encodings include ISO-8859-1, UTF-7, and UTF-8. When an encoding is not specified, a downstream component may choose a different encoding, either by assuming a default encoding or automatically inferring which encoding is being used, which can be erroneous. When the encodings are inconsistent, the downstream component might treat some character or byte sequences as special, even if they are not special in the original encoding. Attackers might then be able to exploit this discrepancy and conduct injection attacks; they even might be able to bypass protection mechanisms that assume the original encoding is also being used by the downstream component.
- The problem of inconsistent output encodings often arises in web pages. If an encoding is not specified in an HTTP header, web browsers often guess about which encoding is being used. This can open up the browser to subtle XSS attacks.
Mitigation MIT-43
With Struts, write all data from form beans with the bean's filter attribute set to true.
Mitigation MIT-31
Strategy: Attack Surface Reduction
To help mitigate XSS attacks against the user's session cookie, set the session cookie to be HttpOnly. In browsers that support the HttpOnly feature (such as more recent versions of Internet Explorer and Firefox), this attribute can prevent the user's session cookie from being accessible to malicious client-side scripts that use document.cookie. This is not a complete solution, since HttpOnly is not supported by all browsers. More importantly, XmlHttpRequest and other powerful browser technologies provide read access to HTTP headers, including the Set-Cookie header in which the HttpOnly flag is set.
Mitigation MIT-5
Strategy: Input Validation
- Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does.
- When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules. As an example of business rule logic, "boat" may be syntactically valid because it only contains alphanumeric characters, but it is not valid if the input is only expected to contain colors such as "red" or "blue."
- Do not rely exclusively on looking for malicious or malformed inputs. This is likely to miss at least one undesirable input, especially if the code's environment changes. This can give attackers enough room to bypass the intended validation. However, denylists can be useful for detecting potential attacks or determining which inputs are so malformed that they should be rejected outright.
- When dynamically constructing web pages, use stringent allowlists that limit the character set based on the expected value of the parameter in the request. All input should be validated and cleansed, not just parameters that the user is supposed to specify, but all data in the request, including hidden fields, cookies, headers, the URL itself, and so forth. A common mistake that leads to continuing XSS vulnerabilities is to validate only fields that are expected to be redisplayed by the site. It is common to see data from the request that is reflected by the application server or the application that the development team did not anticipate. Also, a field that is not currently reflected may be used by a future developer. Therefore, validating ALL parts of the HTTP request is recommended.
- Note that proper output encoding, escaping, and quoting is the most effective solution for preventing XSS, although input validation may provide some defense-in-depth. This is because it effectively limits what will appear in output. Input validation will not always prevent XSS, especially if you are required to support free-form text fields that could contain arbitrary characters. For example, in a chat application, the heart emoticon ("<3") would likely pass the validation step, since it is commonly used. However, it cannot be directly inserted into the web page because it contains the "<" character, which would need to be escaped or otherwise handled. In this case, stripping the "<" might reduce the risk of XSS, but it would produce incorrect behavior because the emoticon would not be recorded. This might seem to be a minor inconvenience, but it would be more important in a mathematical forum that wants to represent inequalities.
- Even if you make a mistake in your validation (such as forgetting one out of 100 input fields), appropriate encoding is still likely to protect you from injection-based attacks. As long as it is not done in isolation, input validation is still a useful technique, since it may significantly reduce your attack surface, allow you to detect some attacks, and provide other security benefits that proper encoding does not address.
- Ensure that you perform input validation at well-defined interfaces within the application. This will help protect the application even if a component is reused or moved elsewhere.
Mitigation MIT-21
Strategy: Enforcement by Conversion
When the set of acceptable objects, such as filenames or URLs, is limited or known, create a mapping from a set of fixed input values (such as numeric IDs) to the actual filenames or URLs, and reject all other inputs.
Mitigation MIT-29
Strategy: Firewall
Use an application firewall that can detect attacks against this weakness. It can be beneficial in cases in which the code cannot be fixed (because it is controlled by a third party), as an emergency prevention measure while more comprehensive software assurance measures are applied, or to provide defense in depth [REF-1481].
Mitigation MIT-16
Strategy: Environment Hardening
When using PHP, configure the application so that it does not use register_globals. During implementation, develop the application so that it does not rely on this feature, but be wary of implementing a register_globals emulation that is subject to weaknesses such as CWE-95, CWE-621, and similar issues.
CAPEC-209: XSS Using MIME Type Mismatch
An adversary creates a file with scripting content but where the specified MIME type of the file is such that scripting is not expected. The adversary tricks the victim into accessing a URL that responds with the script file. Some browsers will detect that the specified MIME type of the file does not match the actual type of its content and will automatically switch to using an interpreter for the real content type. If the browser does not invoke script filters before doing this, the adversary's script may run on the target unsanitized, possibly revealing the victim's cookies or executing arbitrary script in their browser.
CAPEC-588: DOM-Based XSS
This type of attack is a form of Cross-Site Scripting (XSS) where a malicious script is inserted into the client-side HTML being parsed by a web browser. Content served by a vulnerable web application includes script code used to manipulate the Document Object Model (DOM). This script code either does not properly validate input, or does not perform proper output encoding, thus creating an opportunity for an adversary to inject a malicious script launch a XSS attack. A key distinction between other XSS attacks and DOM-based attacks is that in other XSS attacks, the malicious script runs when the vulnerable web page is initially loaded, while a DOM-based attack executes sometime after the page loads. Another distinction of DOM-based attacks is that in some cases, the malicious script is never sent to the vulnerable web server at all. An attack like this is guaranteed to bypass any server-side filtering attempts to protect users.
CAPEC-591: Reflected XSS
This type of attack is a form of Cross-Site Scripting (XSS) where a malicious script is "reflected" off a vulnerable web application and then executed by a victim's browser. The process starts with an adversary delivering a malicious script to a victim and convincing the victim to send the script to the vulnerable web application.
CAPEC-592: Stored XSS
An adversary utilizes a form of Cross-site Scripting (XSS) where a malicious script is persistently "stored" within the data storage of a vulnerable web application as valid input.
CAPEC-63: Cross-Site Scripting (XSS)
An adversary embeds malicious scripts in content that will be served to web browsers. The goal of the attack is for the target software, the client-side browser, to execute the script with the users' privilege level. An attack of this type exploits a programs' vulnerabilities that are brought on by allowing remote hosts to execute code and scripts. Web browsers, for example, have some simple security controls in place, but if a remote attacker is allowed to execute scripts (through injecting them in to user-generated content like bulletin boards) then these controls may be bypassed. Further, these attacks are very difficult for an end user to detect.
CAPEC-85: AJAX Footprinting
This attack utilizes the frequent client-server roundtrips in Ajax conversation to scan a system. While Ajax does not open up new vulnerabilities per se, it does optimize them from an attacker point of view. A common first step for an attacker is to footprint the target environment to understand what attacks will work. Since footprinting relies on enumeration, the conversational pattern of rapid, multiple requests and responses that are typical in Ajax applications enable an attacker to look for many vulnerabilities, well-known ports, network locations and so on. The knowledge gained through Ajax fingerprinting can be used to support other attacks, such as XSS.