CVE-2026-31153
⚪ Do wiadomości
Wrażliwość XSS w Bynder umożliwia atakującym wykonanie dowolnych skryptów webowych.
CVSS
5.4
EPSS
0.1%
Exploit
none
Vendor
Opis źródłowy (NVD)
A stored cross-site scripting (XSS) vulnerability in Bynder v0.1.394 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NOTE: this is disputed by the Supplier because v0.1.394 was never a valid version number, and because there is no available information on what v0.1.394 system or environment may have been used for this XSS finding.
xss
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.4 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.1% |
| Opublikowano (NVD) | 2026-04-06 15:17:09 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-27 06:16:57 UTC |
Referencje
- https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2026-31153 (cve@mitre.org)
- https://www.bynder.com/en/ (cve@mitre.org)