Ad

CVE-2026-36470

NONE
Обновлено 21 сентября 2026
PHP
Параметр Значение
Поставщик PHP
Публичный эксплойт Нет

CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the "Referer" header is copied into the response HTML unmodified/unescaped during POST messages to index.php.