CVE-2026-1819Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Karel Electronics Industry and Trade Inc. ViPort allows Stored XSS. This issue affects ViPort: through 23012026.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 4 mentions (2026-02-04); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-02-04: 4Mentions · 2026-02-09: 1Patch / Workaround · 2026-02-04: 1Technical Details · 2026-02-04: 4Technical Details · 2026-02-09: 102-0402-09
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-044
Disclosure3Patch1
2026-02-091
Disclosure1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-1819 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Karel Electronics Industry and Trade Inc. ViPort allows Sto… https://www.cve.org/CVERecord?id=CVE-2026-1819

    Post summary

    The text announces the disclosure of CVE-2026-1819, an XSS vulnerability in Karel Electronics' ViPort, providing basic technical details but no PoC, exploit code, or patch information.

    00020318
    56.5K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-1819 (CVSS:8.8, HIGH) is Awaiting Analysis. Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Karel Elect..https://nvd.nist.gov/vuln/detail/CVE-2026-1819 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post reports CVE‑2026‑1819 as awaiting analysis, noting its high CVSS score and XSS nature, but does not provide any exploit, patch, or active‑exploitation information.

    0000031
    171 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1819 Stored XSS in Karel Electronics ViPort Through Version 23012026 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1819

    Post summary

    The text announces a stored XSS vulnerability in Karel Electronics ViPort (up to version 23012026) but offers no PoC, exploit code, mitigation, or evidence of active exploitation.

    0000057
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-1819: HIGH] Critical XSS vulnerability discovered in Karel Electronics' ViPort up to 23012026 version, enabling stored XSS attacks. Update your system to stay protected.#cve,CVE-2026-1819,#cybersecurity https://cvefind.com/CVE-2026-1819

    Post summary

    The post highlights a high‑severity stored XSS vulnerability in Karel Electronics' ViPort and urges users to apply updates to mitigate the risk.

    0000046
    583 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-1819 - High Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Karel Electronics Industry and Trade Inc. ViPort allows Stored XSS.This issue affec... https://www.thehackerwire.com/vulnerability/CVE-2026-1819/ https://t.co/Op8ELraHMM

    Post summary

    A stored XSS vulnerability (CVE‑2026‑1819) has been disclosed in Karel Electronics' ViPort system. No PoC, exploit, active exploitation, or patch information is provided.

    0000042
    113 followersView on X

Explore more