
CVE-2026-7429 SSCMS v7.4.0 contains a reflected cross-site scripting vulnerability in the STL processing endpoint that allows attackers to execute arbitrary JavaScript by crafting ma… https://www.cve.org/CVERecord?id=CVE-2026-7429
Post summary
The statement announces a reflected XSS flaw (CVE-2026-7429) in SSCMS v7.4.0 that permits arbitrary JavaScript execution via crafted requests.

