← volver
CVE-2026-50229mediumCWE-80

Apache Tomcat: XSS in number guess example

28Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendcvss 6.1epss 4.2%
de la publicación al arma9 días
Publicada en NVD29 jun
1ª PoC+9d
probabilidad de explotación
4.2%top 10% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
PoCs públicas encontradas1
githubgithub.com/zero-trace7/CVE-2026-502290
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.