SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-5005

MEDIUM · CVSS 5.4 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

The OKRs & Goals application from Twiser Informatics Technology Consulting is vulnerable to a stored cross-site scripting (XSS) attack due to improper input handling during web page generation. This vulnerability could allow an attacker to inject malicious scripts that execute in the context of a user's session, potentially compromising sensitive data or user accounts. Organizations using versions 28220 through 28398 should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-5005
Severity
MEDIUM
CVSS
5.4
EPSS
0.13%

Original NVD Description

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics Technology Consulting, Trade and Education Inc. OKRs & Goals allows Stored XSS. This issue affects OKRs & Goals: from 28220 before 28398.