CVE-2026-71454
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63 allows Cross-Site Scripting (XSS). This issue affects CAPEC-63: before 3.0b63.
- Published Oct 1, 2026
- CVSS 5.8 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available