Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Steedos Platform through 3.0.15-beta.47 contains a reflected cross-site scripting vulnerability in the anonymous /api/page/render endpoint that fails to properly escape query parameters in inline script elements. Attackers can craft malicious links with script-terminating sequences in the schemaApi or data parameters to execute arbitrary JavaScript in victim sessions and steal X-Auth-Token credentials. | |
| Title | Steedos Platform through 3.0.15-beta.47 Reflected XSS via page render | |
| First Time appeared |
Steedos
Steedos steedos-platform |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:steedos:steedos-platform:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Steedos
Steedos steedos-platform |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T12:40:04.172Z
Reserved: 2026-09-15T10:42:43.305Z
Link: CVE-2026-91922
Updated: 2026-09-15T12:39:59.318Z
Status : Received
Published: 2026-09-15T11:17:12.737
Modified: 2026-09-15T13:16:46.797
Link: CVE-2026-91922
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')