Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 21 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Reflected XSS via Arbitrary URL Parameter Naming in CuteNews 2.1.2 | |
| Weaknesses | CWE-79 |
Mon, 21 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitrarily named URL parameter key, with part of its name containing any URL-encoded common XSS payload (such as "><script>alert(1)</script>). | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-21T16:23:09.782Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-36468
No data.
Status : Received
Published: 2026-09-21T16:17:07.710
Modified: 2026-09-21T17:17:34.720
Link: CVE-2026-36468
No data.
OpenCVE Enrichment
Updated: 2026-09-21T17:00:09Z
