CVE-2026-55630
Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted unsanitized user input and rendered stored values verbatim, creating an opportunity for cross-site scripting. Official Docker images and unmodified Kiwi TCMS middleware send a Content-Security-Policy header that blocks inline JavaScript, making exploitation difficult in default deployments, while customized deployments that weaken those security settings may remain vulnerable. Version 16.1 properly sanitizes both fields and resets existing database records that do not validate to null. This issue is fixed in version 16.1.
Scoring
- Severity
- NONE
- CVSS base score
- 0
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N
- EPSS probability
- 0.32%
- CWE
- CWE-79
- Published
- 2026-09-15
- Last modified
- 2026-09-17
Affected products
- kiwitcms Kiwi
Weakness type
Related vulnerabilities
- CVE-2026-78252 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-90943 — parallax filament-comments through 3.0.0 Stored XSS via Comment Body
- CVE-2026-90561 — Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYG
- CVE-2026-89256 — AVideo Bookmark Plugin Stored XSS via Chapter Names
- CVE-2026-89255 — AVideo LoginControl Stored XSS via PGP Public Key
- CVE-2026-89254 — AVideo CustomizeUser Stored XSS via field_name Parameter
- CVE-2026-89253 — AVideo Stored XSS via donationLink in watch page button
- CVE-2026-89249 — AVideo YPTWallet Stored XSS via CryptoWallet Configuration