CVE-2026-19988Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in Alaev SEO Tools Extension up to 1.0.10 on Chrome. This impacts the function addDiv of the file src/popup.html of the component Popup UI. Performing a manipulation results in basic cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-80

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-17: 3Technical Details · 2026-08-17: 208-17
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19988 A vulnerability was detected in Alaev SEO Tools Extension up to 1.0.10 on Chrome. This impacts the function addDiv of the file src/popup.html of the component Popup U… https://www.cve.org/CVERecord?id=CVE-2026-19988 ----- Traducción: Se detectó una vul… https://infoflow.cloud`

    Post summary

    A new CVE-2026-19988 was reported for the Alaev SEO Tools Extension affecting the addDiv function in src/popup.html, with only the CVE reference provided and no further exploit, patch, or technical details.

    0000026
    100 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19988 A vulnerability was detected in Alaev SEO Tools Extension up to 1.0.10 on Chrome. This impacts the function addDiv of the file src/popup.html of the component Popup U… https://www.cve.org/CVERecord?id=CVE-2026-19988

    Post summary

    The post briefly discloses CVE-2026-19988, noting its impact on the addDiv function in the Alaev SEO Tools Extension, without providing proof‑of‑concept, exploit, or mitigation details.

    000001.3K
    58.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-19988 Remote Cross-Site Scripting in Alaev SEO Tools Extension 1.0.10 on Chrome https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-19988

    Post summary

    The text references CVE‑2026‑19988 as a remote XSS issue in the Alaev SEO Tools Extension for Chrome, but lacks details on exploitation tools, active use, or remediation.

    00000116
    4.1K followersView on X

Explore more