CVE-2026-41031
Received
Received - Intake
Stored XSS in Vinna Process Monitor
Publication date: 2026-06-09
Last updated on: 2026-06-09
Assigner: CERT VDE
Description
Description
A Stored Cross-Site Scripting vulnerability in Vinna Process Monitor Version 4.0 Service Pack 1 (Build 63255) allows an authenticated remote attacker with low privileges to inject malicious JavaScript code into the application. This enables attackers to steal administrative access tokens and session credentials.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| vinna | process_monitor | 4.0_service_pack_1 |
| skilja | vinna_process_monitor | From 3.1.0 (inc) to 3.1.4 (inc) |
| skilja | vinna_process_monitor | From 4.0.0 (inc) to 4.0.6 (inc) |
| skilja | vinna_process_monitor | 4.0.7 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |