PULSE
LIVE28signals / 24h
FEED
ransomqilin reclama a TenSparrows · US · Not Foundransomcmdorganization reclama a Collge Mont Notre-Dame de Sherbrooke · CA · Educationransomqilin reclama a Db Tarimsal Enerji · TR · Agriculture and Food Productionransomcmdorganization reclama a Rondout Electric · US · Energy & Utilitiesransomqilin reclama a Byonyks · US · Technologyransomqilin reclama a Prenisac · US · Not Foundransomqilin reclama a Excel Consultores · MX · Professional Servicesransomqilin reclama a Affinity Capital · US · Financial Servicesransomkairos reclama a Warwick Fabrics · NZ · Manufacturingransomgunra reclama a Siam Stabilizers and Chemicals Co., Ltd. / SSC · TH · Manufacturingransomqilin reclama a Adpo · Otherransomqilin reclama a servitelco · CL · Technologyransomqilin reclama a Orimar · BE · Otherransomqilin reclama a Indian Motos Inmot · EC · Manufacturingransomqilin reclama a TenSparrows · US · Not Foundransomcmdorganization reclama a Collge Mont Notre-Dame de Sherbrooke · CA · Educationransomqilin reclama a Db Tarimsal Enerji · TR · Agriculture and Food Productionransomcmdorganization reclama a Rondout Electric · US · Energy & Utilitiesransomqilin reclama a Byonyks · US · Technologyransomqilin reclama a Prenisac · US · Not Foundransomqilin reclama a Excel Consultores · MX · Professional Servicesransomqilin reclama a Affinity Capital · US · Financial Servicesransomkairos reclama a Warwick Fabrics · NZ · Manufacturingransomgunra reclama a Siam Stabilizers and Chemicals Co., Ltd. / SSC · TH · Manufacturingransomqilin reclama a Adpo · Otherransomqilin reclama a servitelco · CL · Technologyransomqilin reclama a Orimar · BE · Otherransomqilin reclama a Indian Motos Inmot · EC · Manufacturing
← All CVEs
CVE WatchJul 30, 2026

CVE-2026-18360

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes f

CVSS

7.6

High

EPSS

KEV

Exploit Today

0

0-100

Published: Jul 30, 2026 · Last modified: Jul 30, 2026 · CWE-79

EPSS · 30d

Not enough EPSS history yet.

Technical description

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-183617.6 HIG
0The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.4h
CVE-2026-169697.6 HIG
0The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets function.4h
CVE-2026-30934.7 MED
0GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an attacker to execute arbitrary JavaScript in another user's browser via a crafted URL, due to improper sanitization of user-controlled input.18h
CVE-2026-664906.1 MED
0Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.223h
CVE-2026-659466.1 MED
0Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.023h
CVE-2026-87916.4 MED
0The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` setting in all versions up to, and including, 1.0.17 due to a missing capability check on the `set_options` AJAX action when the plugin is operating in agency mode. The `trafftSetOptions()` handler verifies a nonce that is exposed to any authenticated user (it is printed inline on every admin page, including profile.php) but performs no capability check before calling `update_option('trafft_option', ['bookingWebsiteUrl' => ...])`. This setting is then used by `trafftAdminAssets()` to enqueue `<bookingWebsiteUrl>/embed.js` as a script on every front-end page that renders the booking shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to point the embed-script URL at an attacker-controlled origin and execute arbitrary JavaScript in the browser of every site visitor (including admins).22h