CVE-2026-32774
Vulnogram - Stored Cross-Site Scripting via Comment Hypertext
Vulnogram 1.0.0 contains a stored cross-site scripting vulnerability in comment hypertext handling that allows attackers to inject malicious scripts. Remote attackers can inject XSS payloads through comments to execute arbitrary JavaScript in victims' browsers.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Produtos afetados
Vulnogram · VulnogramQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://github.com/Vulnogram/Vulnogramhttps://github.com/Vulnogram/Vulnogram/commit/2f0e21b113c58124084c7b74c9768fc241126a05https://github.com/Vulnogram/Vulnogram/security/advisories/GHSA-pg4p-2985-gvxrhttps://www.vulncheck.com/advisories/vulnogram-stored-cross-site-scripting-via-comment-hypertext