CVE-2026-66146
Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker to execute javascript script in a user's browser.
- Published Aug 11, 2026
- CVSS 6.1 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)