CVE-2026-4355Disclosure

LOWCVSS 2.0 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in Portabilis i-Educar 2.11. This impacts an unknown function of the file /intranet/educar_servidor_curso_lst.php of the component Endpoint. Performing a manipulation of the argument Name results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-18); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-18: 3Mentions · 2026-03-19: 1Technical Details · 2026-03-18: 203-1803-19
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-183
Disclosure3
2026-03-191
General1
Full discourse4 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4355 📊 Severity: 3.5 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4355 #CVE-2026-4355 #CVE #Low  #CyberSecurity #InfoSec https://t.co/YSkvsBk7M7

    Post summary

    The tweet announces a low‑severity CVE (CVE‑2026‑4355) with no details on exploitation, patching, or technical specifics.

    0000037
    104 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4355 Cross-Site Scripting in Portabilis i-Educar 2.11 via Endpoint Name Argument https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4355

    Post summary

    The text announces CVE‑2026‑4355, describing a cross‑site scripting flaw in Portabilis i‑Educar 2.11 that targets the Endpoint Name argument, but it does not mention PoCs, active exploitation, patches, or exploit tools.

    0000031
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4355 A vulnerability was detected in Portabilis i-Educar 2.11. This impacts an unknown function of the file /intranet/educar_servidor_curso_lst.php of the component Endpoint… https://www.cve.org/CVERecord?id=CVE-2026-4355

    Post summary

    The message announces CVE-2026-4355 in Portabilis i-Educar 2.11, noting an unknown function in a specific file, but provides no further technical or remediation details.

    00000118
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4355 - Portabilis i-Educar Endpoint educar_servidor_curso_lst.php cross site scripting Intel Report: https://ift.tt/5iAxh1o

    Post summary

    An alert announces a new XSS vulnerability (CVE‑2026‑4355) affecting Portabilis i‑Educar's educar_servidor_curso_lst.php endpoint.

    0000038
    335 followersView on X

Explore more