CVE-2026-36470
CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the "Referer" header is copied into the response HTML unmodified/unescaped during POST messages to index.php.
- Published Sep 21, 2026
- CVSS 5.8 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)