PULSE
FEED
ransomsilentransomgroup reclama a N... · Not Foundransomsilentransomgroup reclama a S... · Not Foundransommetaencryptor reclama a GE Vernova Inc. · US · Energy & Utilitiesransommetaencryptor reclama a PKF Hadiwinata · ID · Professional Servicesransommetaencryptor reclama a Platinum Healthcare Staffing · US · Healthcareransomemperador reclama a Electrolux & Ontrac · Manufacturingransomeverest reclama a Securitas Group · SE · Professional Servicesransomeverest reclama a Morula IVF · ZA · Healthcareransomwallstreet reclama a Tobin & Company · US · Financial Servicesransomwallstreet reclama a Ar Valve Resources · GB · Energy & Utilitiesransomwallstreet reclama a GTFM · US · Not Foundransomwallstreet reclama a Beatus Cartons · GB · Manufacturingransomeverest reclama a Reliance Audit · Professional Servicesransomeverest reclama a UNIRITA · JP · Technologyransomsilentransomgroup reclama a N... · Not Foundransomsilentransomgroup reclama a S... · Not Foundransommetaencryptor reclama a GE Vernova Inc. · US · Energy & Utilitiesransommetaencryptor reclama a PKF Hadiwinata · ID · Professional Servicesransommetaencryptor reclama a Platinum Healthcare Staffing · US · Healthcareransomemperador reclama a Electrolux & Ontrac · Manufacturingransomeverest reclama a Securitas Group · SE · Professional Servicesransomeverest reclama a Morula IVF · ZA · Healthcareransomwallstreet reclama a Tobin & Company · US · Financial Servicesransomwallstreet reclama a Ar Valve Resources · GB · Energy & Utilitiesransomwallstreet reclama a GTFM · US · Not Foundransomwallstreet reclama a Beatus Cartons · GB · Manufacturingransomeverest reclama a Reliance Audit · Professional Servicesransomeverest reclama a UNIRITA · JP · Technology
← Todos los CVEs
CVE Watch25 sept 2026

CVE-2026-84463

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a user with Knowledge Base editing rights for a category

CVSS

—

Sin CVSS

EPSS

—

KEV

—

Exploit Today

—

0-100

Publicado: 25 sept 2026 · Última mod.: 25 sept 2026 · CWE-79 · CWE-352 · CWE-838

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a user with Knowledge Base editing rights for a category can embed a video widget in a published answer with a specially crafted value. When the answer is rendered, that value is inserted into the page's HTML without being escaped for its attribute context, allowing it to break out and inject additional HTML into the page. When another user who has permission to switch between user sessions views the affected answer, the injected HTML causes their browser to silently send a request to Zammad's session-switching endpoint using their own active credentials. This results in switching their session to an account chosen by the person who wrote the Knowledge Base answer. No action is required from the viewer beyond opening the published answer. This issue is fixed in version 7.1.2.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-86066—
—
———Horilla is an HR and CRM software. Prior to 2.0.0, approve_validate_attendance_request at /attendance/approve-validate-attendance-request/ changes attendance_validated, is_validate_request_approved, approved_by, and related pending-request state through an HTTP GET before calling attendance.save(), so Django does not require CSRF validation for the action. An unauthenticated attacker can cause a logged-in manager with attendance.change_attendance to make a top-level request that carries the manager's SameSite=Lax session cookie, silently approving attendance with the victim's privileges and attributing the approval to the victim in the audit trail. This issue is fixed in version 2.0.0.3h
CVE-2026-71483—
—
———Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected by jQuery .html() in employee/templates/employee_nav.html without HTML neutralization. An external attacker can craft and deliver a link that causes JavaScript to execute when an authenticated employee or administrator reaches the employee filter, allowing access to browser-visible session data and actions with the victim's application privileges. This issue is fixed in version 1.6.0.4h
CVE-2026-100383—
—
———Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - WikiLambda Extension: 1.47.0-alpha. The issue has been remediated on the `master` branch.4h
CVE-2026-100381—
—
———Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - UploadWizard Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - UploadWizard Extension: from * before 1.46.1, 1.45.5, 1.43.10.4h
CVE-2026-100380—
—
———Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - Wikibase Extension: from * before 1.46.1, 1.45.5, 1.43.10.5h
CVE-2026-100376—
—
———Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - TemplateSandbox Extension: from * before 1.46.1, 1.45.5, 1.43.10.5h