
CVE-2026-22438 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree TheBi thebi allows Reflected XSS.This issue affe… https://www.cve.org/CVERecord?id=CVE-2026-22438
Post summary
The excerpt references a newly disclosed reflected XSS vulnerability (CVE‑2026‑22438) in foreverpinetree’s TheBi module, providing only the type of flaw without noting any exploit, PoC, patch, or active exploitation.
