CVE-2026-1959Disclosure

LOWCVSS 5.1 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes, via the 'descripción' parameter in the '/loggrodemo/jbrain/MaestraCuentasBancarias' endpoint.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 4 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-02-09)
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-06: 1Mentions · 2026-02-07: 1Mentions · 2026-02-09: 2Technical Details · 2026-02-09: 202-0602-0702-09
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-061
Disclosure1
2026-02-071
Disclosure1
2026-02-092
Disclosure2
Full discourse4 posts
  • David Padilla@ciberpadi
    Disclosure

    I'm very pleased to have reached 10 CVE's personally following the recent assignment of: - CVE-2026-1959 - CVE-2026-1960 Many thanks to CNA @INCIBE for handling the vulnerability report responsibly. Link: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-loggro-pymes-web-application https://t.co/x0eVS8iOx8

    Post summary

    The user announces that they have been assigned two CVEs (CVE‑2026‑1959 and CVE‑2026‑1960) after a report was responsibly handled by INCIBE, with no additional exploitation or remediation details.

    01090446
    1.6K followersView on X
  • INCIBE-CERT@incibe_cert
    Disclosure

    ⚠️#INCIBEaviso | Múltiples vulnerabilidades en la aplicación web de #LoggroPymes #CVE CVE-2026-1959 CVE-2026-1960 https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-la-aplicacion-web-de-loggro-pymes #AvisosDeSeguridad #TI #CNA #0day https://t.co/4zULX6BdVj

    Post summary

    The tweet announces the existence of multiple CVEs (CVE-2026-1959 and CVE-2026-1960) affecting the LoggroPymes web application, but provides no further technical or exploitation details.

    03040489
    42.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1959 Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes, via the 'descripción' parameter in the '/loggrodemo/jbrain/MaestraCuentasBancarias' endpoint. https://www.cve.org/CVERecord?id=CVE-2026-1959

    Post summary

    The post discloses a stored XSS vulnerability in Loggro Pymes via the descripción parameter on a specific endpoint, but provides no PoC, exploit, or patch information.

    00010197
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1959 Stored Cross-Site Scripting in Loggro Pymes Web Application Version 1.0.124 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1959

    Post summary

    CVE-2026-1959 is a stored XSS flaw in Loggro Pymes Web Application v1.0.124; the text provides the vulnerability type but no PoC, exploit, patch, or evidence of active exploitation.

    0000051
    4.0K followersView on X

Explore more