CVE-2026-82483
A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_in
CVSS
3.5
Low
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Aug 30, 2026 · Last modified: Aug 30, 2026 · CWE-79 · CWE-94
Not enough EPSS history yet.
A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden Album Update Endpoint. The manipulation results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. Upgrading to version 1.6.29 will fix this issue. It is recommended to upgrade the affected component.
- github.comhttps://github.com/Leousum/VulnPoC/blob/main/CPG1.6.x/stored_xss_album_desc.md
- github.comhttps://github.com/coppermine-gallery/cpg1.6.x/releases/tag/v1.6.29
- vuldb.comhttps://vuldb.com/cve/CVE-2026-82483
- vuldb.comhttps://vuldb.com/submit/888335
- vuldb.comhttps://vuldb.com/vuln/397033
- vuldb.comhttps://vuldb.com/vuln/397033/cti
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-824883.5 LOW—
——0A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component User Management. The manipulation of the argument Username leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.2hCVE-2026-824823.5 LOW—
——0A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the component edit_profile Endpoint. The manipulation of the argument Biography leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 1.6.29 mitigates this issue. Upgrading the affected component is recommended.6hCVE-2026-824516.1 MED—
——0Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel.23hCVE-2026-765466.8 MED4.7%
——1The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, allowing users with a role as low as contributor to perform Stored Cross-Site Scripting attacks against any user viewing the affected content, including administrators. The shortcode is not enabled by default.12hCVE-2026-556964.3 MED12.9%
——4PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, AttachmentViewer.setAttachment in js/privatebin.js uses getAttachmentMimeType to accept attacker-controlled MIME types and uses getBlobUrl to create a same-origin blob before setting attachmentLink's href for the Download attachment link. The SVG-only sanitization branch updates only the preview blob, so text/html, image/svg, application/xhtml+xml, and text/xml attachments can remain active in the download blob. On an instance with fileupload = true and a weakened, stripped, or absent Content Security Policy, an anonymous attacker can create such an attachment, and a victim who opens the link in a new tab causes inline JavaScript to execute in the PrivateBin origin. The script can read origin-scoped local storage and issue same-origin requests, including requests to applications co-hosted on the same domain. This issue is fixed in version 2.0.5.2dCVE-2026-192869.8 CRI46.4%
——14IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.2d