
CVE-2026-1238、Adobe Acrobat ReaderにXSSの脆弱性。CVSSスコアは6.5。早急にアップデートを実施すべき。影響は大きい。
Post summary
The post discloses CVE-2026-1238, an XSS flaw in Adobe Acrobat Reader with a CVSS 6.5 score, and urges users to update immediately due to high impact.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fh' (fingerprint) parameter in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
AVAILABLE
Momentum
STABLE
| Date | Total | Labels |
|---|
| 2026-03-19 | 3 | Disclosure3 |
| 2026-06-12 | 1 | Disclosure1 |
| 2026-06-13 | 1 | Disclosure1 |

CVE-2026-1238、Adobe Acrobat ReaderにXSSの脆弱性。CVSSスコアは6.5。早急にアップデートを実施すべき。影響は大きい。
Post summary
The post discloses CVE-2026-1238, an XSS flaw in Adobe Acrobat Reader with a CVSS 6.5 score, and urges users to update immediately due to high impact.

CVE-2026-1238: Adobe製品に関連するゼロデイ脆弱性が確認され、影響は複数の主要製品。早急なパッチ情報のリリースが期待される。
Post summary
A zero‑day vulnerability (CVE‑2026‑1238) affecting several major Adobe products has been confirmed, with expectations of an imminent patch release.

CVE-2026-1238 Unauthenticated Stored XSS in SlimStat Analytics WordPress Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1238
Post summary
The text discloses a new stored XSS vulnerability in the SlimStat Analytics WordPress Plugin, specifying the vulnerability type and target, but does not mention any PoC, exploit, active exploitation, patch, or debunking.

CVE-2026-1238 The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fh' (fingerprint) parameter in all versions up to, and including, 5.3.… https://www.cve.org/CVERecord?id=CVE-2026-1238
Post summary
CVE-2026-1238 reveals a stored XSS in the SlimStat Analytics WordPress plugin (up to version 5.3) through the 'fh' parameter, with no evidence of exploitation or patching mentioned.

CVE Alert: CVE-2026-1238 - veronalabs - SlimStat Analytics - https://www.redpacketsecurity.com/cve-alert-cve-2026-1238-veronalabs-slimstat-analytics/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-1238 #veronalabs #slimstat-analytics
Post summary
The tweet announces a CVE alert for CVE‑2026‑1238 affecting veronalabs SlimStat Analytics, but provides no further technical specifics or evidence of exploitation.