CVE-2026-37710

Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote attacker to execute arbitrary code via the site navigation custom URL function

  • Published Aug 28, 2026
  • CVSS 6.1 medium
  • 0.5% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

CVE-2026-37710 at the National Vulnerability Database