CVE-2026-27176Disclosure(mjdm / majordomo)

LOWCVSS 5.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

MajorDoMo (aka Major Domestic Module) contains a reflected cross-site scripting (XSS) vulnerability in command.php. The $qry parameter is rendered directly into the HTML page without sanitization via htmlspecialchars(), both in an input field value attribute and in a paragraph element. An attacker can inject arbitrary JavaScript by crafting a URL with malicious content in the qry parameter.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • majordomo

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-18); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
majordomo

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-18: 1Mentions · 2026-02-19: 1Mentions · 2026-05-05: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-19: 1Technical Details · 2026-05-05: 102-1802-1905-05
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-27176 - medium 🚨 MajorDoMo - Cross-Site Scripting > MajorDoMo contains a reflected XSS caused by unsanitized $qry parameter in http://command.ph... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-27176 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet discloses a medium‑severity reflected XSS flaw in MajorDoMo triggered by the $qry parameter and links to a ProjectDiscovery library for detection, without mentioning active exploitation or mitigation.

    00002136
    944 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27176 Reflected Cross-Site Scripting Vulnerability in MajorDoMo Command Interface https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27176

    Post summary

    The text announces a reflected XSS vulnerability (CVE‑2026‑27176) in MajorDoMo’s command interface, providing only a brief description and a link for more details.

    0001044
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27176 MajorDoMo (aka Major Domestic Module) contains a reflected cross-site scripting (XSS) vulnerability in command.php. The $qry parameter is rendered directly into the H… https://www.cve.org/CVERecord?id=CVE-2026-27176

    Post summary

    A reflected XSS vulnerability in MajorDoMo’s command.php, affecting the $qry parameter, is disclosed with no evidence of exploitation, PoC, or patch.

    00000125
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmjdmmajordomo---

Explore more