CVE-2026-19434
Received Received - Intake

Cross-Site Scripting in Pentestify via Severity Field

Vulnerability report for CVE-2026-19434, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: 4daa8cea-433a-44bd-9456-53b127fc289a

Description

Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the application origin via HTML markup stored in a finding's severity field, which the frontend interpolates unescaped into class and style attributes when rendering the report.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ccyl13 pentestify to 2.3.1 (exc)
ccyl13 pentestify 2.3.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-19434 is a stored cross-site scripting (XSS) vulnerability in Pentestify before version 2.3.1. Authenticated users can inject malicious JavaScript into the severity field of a finding. When the report is rendered, the frontend interpolates this unescaped input into HTML class and style attributes, allowing arbitrary script execution in the application's origin.

Impact Analysis

An attacker with authenticated access could inject malicious scripts that execute when other users view reports. This could lead to session hijacking, data theft, or unauthorized actions performed on behalf of users. The impact depends on user privileges and the application's data sensitivity.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's integrity and confidentiality principles or HIPAA's safeguards for protected health information. Organizations using affected versions may face compliance violations and potential regulatory penalties.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19434. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart