CVE-2026-4816: medium-severity vulnerability in Schiocco Support Board
Reflected Cross Site Scripting (XSS) vulnerability in Support Board
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.8epss 0.2%
exploitation probability
0.2%top 87% of all CVEs
observed exploitation
nono source reports it
A Reflected Cross Site Scripting (XSS) vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the 'search' parameter in '/supportboard/include/articles.php'. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Affected products
Schiocco · Support BoardRelated CVEs — Schiocco Support Board
In the same product, most dangerous first.
CVE-2025-4828CRITICALSupport Board <= 3.8.0 - Unauthenticated Arbitrary File DeletionEPSS 0.9%CVE-2025-54031HIGHWordPress Support Board <= 3.8.0 - Local File Inclusion VulnerabilityEPSS 0.7%CVE-2026-27395CRITICALWordPress Support Board plugin < 3.8.9 - Privilege Escalation vulnerabilityEPSS 0.5%CVE-2025-4855CRITICALSupport Board <= 3.8.0 - Unauthenticated Authorization Bypass due to Use of Default Secret KeyEPSS 0.4%CVE-2026-4815HIGHSQL Injection vulnerability in Support BoardEPSS 0.2%CVE-2025-54027HIGHWordPress Support Board <= 3.8.0 - Cross Site Scripting (XSS) VulnerabilityEPSS 0.2%