CVE-2026-44956Disclosure

LOWCVSS 0.0 · NONE

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Low‑privileged users could use their Full Name as a vector for a stored XSS attack. The name is included in system‑generated emails, whose content is stored in the details field of the userlog table. An admin user viewing the email content through userlog-details.php would have any malicious JavaScript payload executed due to missing output sanitisation. Proper escaping has been added to the userlog details output.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-23: 2Technical Details · 2026-06-23: 206-23
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-44956 Low‑privileged users could use their Full Name as a vector for a stored XSS attack. The name is included in system‑generated emails, whose content is stored in the de… https://www.cve.org/CVERecord?id=CVE-2026-44956 ----- Traducción: CVE-2026-44956 Los… http://infoflow.cloud`

    Post summary

    CVE-2026-44956 is an announced stored XSS vulnerability exploitable through a user's full name in system‑generated emails; no PoC, exploit, patch, or evidence of active exploitation is provided.

    0000029
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44956 Low‑privileged users could use their Full Name as a vector for a stored XSS attack. The name is included in system‑generated emails, whose content is stored in the de… https://www.cve.org/CVERecord?id=CVE-2026-44956

    Post summary

    A brief disclosure of CVE‑2026‑44956, describing a low‑privilege stored XSS vulnerability via the user’s Full Name in system‑generated emails.

    00000712
    57.7K followersView on X

Explore more