CVE-2026-66146

Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker to execute javascript script in a user's browser.

  • Published Aug 11, 2026
  • CVSS 6.1 medium
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-66146 at the National Vulnerability Database