CVE-2026-77490
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C
- CWE
- CWE-79
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Affected products
- Microsoft Microsoft Edge (Chromium-based)
Weakness type
Related vulnerabilities
- CVE-2026-89268 — QloApps through 1.7.0 Reflected XSS via List Filter Parameters
- CVE-2026-90443 — A web interface reflects a portion of the request URL into a script context and a hyperlink...
- CVE-2026-54165 — Stored DOM-XSS in public shared-folder image gallery (one-click, unauthenticated victim)
- CVE-2026-81918 — Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block
- CVE-2026-81917 — Concrete CMS below 9.5.3 is vulnerable to Stored XSS in the Document Library block file description and tags
- CVE-2026-81911 — Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot save_template via Unescaped Summary Description
- CVE-2026-62138 — WordPress Visual Composer Website Builder plugin <= 45.16.1 - Cross Site Scripting (XSS) vulnerability
- CVE-2026-62111 — WordPress Simple Payment plugin <= 2.5.4 - Cross Site Scripting (XSS) vulnerability