SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-38473

MEDIUM · CVSS 5.4 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A stored cross-site scripting (XSS) vulnerability exists in the subtitle deletion process of GazellePW, allowing remote authenticated users to inject malicious JavaScript through specially crafted subtitle filenames. This vulnerability can lead to unauthorized script execution when the stored data is rendered, potentially compromising user sessions or exposing sensitive information. Organizations using GazellePW should prioritize addressing this issue to safeguard against potential exploitation by authenticated users.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-38473
Severity
MEDIUM
CVSS
5.4
EPSS
0.34%
Java

Original NVD Description

A Stored XSS vulnerability in the subtitle deletion flow in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users to inject arbitrary JavaScript via a crafted subtitle filename, which is stored during upload and later rendered in /subtitles.php?action=delete.