CVE-2026-22192 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by importing a cr…
Medium CVSS: 6.3

CVE-2026-22192

wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by importing a crafted options file with unescaped customCss field values. Attackers can supply a malicious JSON import file containing script payloads in the customCss parameter that execute on every page when rendered through the options handler without proper sanitization.
Vendor
Gvectors
Product
Wpdiscuz
CWE
CWE-79
Yayın Tarihi
2026-03-13 19:54:09
Güncelleme
2026-03-17 20:28:18
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar