PULSE
EN VIVO54señales / 24h
FEED
ransomsection9 reclama a ******.net.br · BR · Financial Servicesransomsection9 reclama a ******.com.br · BR · Otherransomsection9 reclama a ********.com.br · BR · Not Foundransomglobal secret group reclama a Prism Telecom · FI · Technologyransomglobal secret group reclama a Cipher Dynamics · IN · Technologyransomglobal secret group reclama a Stratos Network · AE · Technologyransomglobal secret group reclama a OmniLink AG · DE · Technologyransomglobal secret group reclama a Vertex Systems · US · Technologyransomglobal secret group reclama a Nexon Corp. · KR · Technologyransomglobal secret group reclama a Farmers Mutual Fire Insurance · US · Financial Servicesransomglobal secret group reclama a West Sixth Law · US · Professional Servicesransomglobal secret group reclama a Baker Business & Tax Solutions · US · Professional Servicesransomglobal secret group reclama a Carpets Direct · US · Retail & E-Commerceransomglobal secret group reclama a AnyWeather · US · Technologyransomsection9 reclama a ******.net.br · BR · Financial Servicesransomsection9 reclama a ******.com.br · BR · Otherransomsection9 reclama a ********.com.br · BR · Not Foundransomglobal secret group reclama a Prism Telecom · FI · Technologyransomglobal secret group reclama a Cipher Dynamics · IN · Technologyransomglobal secret group reclama a Stratos Network · AE · Technologyransomglobal secret group reclama a OmniLink AG · DE · Technologyransomglobal secret group reclama a Vertex Systems · US · Technologyransomglobal secret group reclama a Nexon Corp. · KR · Technologyransomglobal secret group reclama a Farmers Mutual Fire Insurance · US · Financial Servicesransomglobal secret group reclama a West Sixth Law · US · Professional Servicesransomglobal secret group reclama a Baker Business & Tax Solutions · US · Professional Servicesransomglobal secret group reclama a Carpets Direct · US · Retail & E-Commerceransomglobal secret group reclama a AnyWeather · US · Technology
← Todos los CVEs
CVE Watch22 jul 2026

CVE-2026-24754

Kiteworks is a private data network (PDN). Prior to version 9.3.0, a stored XSS vulnerability in Kiteworks Secure Data Forms could allow an

CVSS

5.4

Medio

EPSS

0.1%

p3

KEV

Exploit Today

1

0-100

Publicado: 1 jun 2026 · Última mod.: 22 jul 2026 · CWE-79

EPSS · 30d
0.1%EPSS · 30 días0.1%
2026-06-302026-07-25
Descripción técnica

Kiteworks is a private data network (PDN). Prior to version 9.3.0, a stored XSS vulnerability in Kiteworks Secure Data Forms could allow an authenticated attacker to execute arbitrary JavaScript code in other users' sessions. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-174968.1 ALT
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to include executable markup such as an img onerror handler. When the user views the chat response, that markup runs as JavaScript in the privileged Tauri webview, enabling arbitrary script execution in the application context (cross-site scripting).4h
CVE-2026-154256.4 MED
10.2%
3The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Slug (post_name) in all versions up to, and including, 28.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires pretty permalinks to be enabled, as the exploit chain depends on get_permalink() embedding the stored percent-encoded post_name in the generated URL.2d
CVE-2026-575315.4 MED
16.4%
5Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows unauthenticated attackers to execute arbitrary JavaScript in the host application's origin by causing a victim to paste attacker-controlled content. The parseDOM.getAttrs handler stores raw innerHTML of pasted span elements with data-type="emoji" without sanitization, and the toMarkdown runner subsequently assigns this unsanitized value directly to a live DOM element's innerHTML, bypassing the DOMPurify sanitization used in the toDOM path, causing payload execution on every markdown serialization cycle.2d
CVE-2026-575305.4 MED
7.5%
2Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary JavaScript in the browser context of any user who opens the document or clicks a rendered link. The parseMarkdown runner stores raw URL values from the remark AST as href mark attributes without URL scheme validation, and the ineffective DOMPurify.sanitize call in edit-view.ts treats the bare URL string as a text node and returns it unchanged, allowing javascript: payloads to pass through the link-tooltip preview component and read-only mode anchor elements unmodified.2d
CVE-2026-83086.1 MED
4.5%
1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services Website Template allows Reflected XSS. This issue affects Website Template: before v2.2d
CVE-2026-55730
28.4%
9Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's browser and perform actions with the victim's privileges via a crafted link containing a malicious `project` or `mspParams` parameter.2d