CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the "Referer" header is copied into the response HTML unmodified/unescaped during POST messages to index.php.
CVE-2026-36470
NONE
Updated Sep 21, 2026
PHP
CVE Details
CVE ID
CVE-2026-36470
Published Date
Sep 21, 2026
Vendor
PHP
Severity
NONE
Impact
Minimal impact
Source
View Advisory