CVE-2026-42615
GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring.
CVSS
7.2
Alto
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Publicado: 29 abr 2026 · Última mod.: 24 jul 2026 · CWE-79
0.3%EPSS · 30 días0.3%
2026-08-102026-09-07
GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-818244.7 MED—
———The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.58mCVE-2026-696904.6 MED—
———Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.39mCVE-2026-696153.5 BAJ—
———Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.39mCVE-2026-694177.3 ALT—
———Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.1hCVE-2026-694027.3 ALT—
———Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.1hCVE-2026-693569.3 CRÍ—
———Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.1h