CVE-2026-36472
5.2 MEDIUMpublic exploit availablePublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw allows a remote attacker to inject arbitrary JavaScript into an authenticated user's session via unsanitized clickable links on the msg_info page, leading to potential data theft or manipulation.
- Exploitability
- Exploitation is moderately easy as it requires control over a javascript: URI and placement of such a link on the msg_info page. Authentication is needed for the target user to be affected.
- Blast radius
- If exploited, this could result in unauthorized access to sensitive information or actions within the authenticated user's session.
- Prioritized remediation
- Update to the latest version of CuteNews which includes fixes for XSS vulnerabilities.
xssauth-requiredweb-app
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allows a remote attacker to execute arbitrary JavaScript in the context of an authenticated user's session via a javascript: URI rendered as an unsanitized clickable link on the msg_info page.
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
Weaknesses
CWE-79
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-11421
- MEDIUMCVE-2025-71419PoC
- MEDIUMCVE-2026-16069
- HIGHCVE-2026-16143
- MEDIUMCVE-2026-16293
- HIGHCVE-2026-16573
- HIGHCVE-2026-17506
- MEDIUMCVE-2026-36468PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.