CVE-2026-36472

CVE-2026-36472 published: CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allows a remote attacker to execute arbitrary JavaScript in the context of an authenticated user's session via a javascript: URI rendered as a...

View full NVD advisory → ← Back to CVE watch