CVE-2026-90443
A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes arbitrary script in the context of the affected application and can redirect the user's browser to an arbitrary external site. Successful exploitation could allow an attacker to act with the compromised user's session privileges within the application.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
- CWE
- CWE-79
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Affected products
- CISA Malcolm
- CISA Malcolm
Weakness type
Related vulnerabilities
- CVE-2026-89268 — QloApps through 1.7.0 Reflected XSS via List Filter Parameters
- CVE-2026-54165 — Stored DOM-XSS in public shared-folder image gallery (one-click, unauthenticated victim)
- CVE-2026-81918 — Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block
- CVE-2026-81917 — Concrete CMS below 9.5.3 is vulnerable to Stored XSS in the Document Library block file description and tags
- CVE-2026-77490 — Microsoft Edge (Chromium-based) Spoofing Vulnerability
- CVE-2026-81911 — Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot save_template via Unescaped Summary Description
- CVE-2026-62138 — WordPress Visual Composer Website Builder plugin <= 45.16.1 - Cross Site Scripting (XSS) vulnerability
- CVE-2026-62111 — WordPress Simple Payment plugin <= 2.5.4 - Cross Site Scripting (XSS) vulnerability