SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-27365

MEDIUM · CVSS 5.9 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The PublishPress Series plugin is vulnerable to a stored cross-site scripting (XSS) attack due to improper input neutralization during web page generation. This vulnerability could allow an attacker to inject malicious scripts that execute in the context of a user's browser, potentially compromising user data and session integrity. Organizations using affected versions of the plugin should prioritize remediation to protect against potential exploitation.

CVE
CVE-2026-27365
Severity
MEDIUM
CVSS
5.9
EPSS
0.14%

Original NVD Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress PublishPress Series allows Stored XSS. This issue affects PublishPress Series: from n/a through 2.17.0.