AUGUST 26, 2026
Live Feed
Back to database
Case File

CVE-2026-50230

MEDIUM · CVSS 6.1 EPSS 0.41%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-06-05 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.1. It affects Java.

CVE
CVE-2026-50230
Severity
MEDIUM
CVSS
6.1
EPSS
0.41%
Java

Original NVD Description

Lyrion Music Server 9.2.0 contains an unauthenticated reflected cross-site scripting vulnerability in the server.log endpoint that allows attackers to inject arbitrary HTML and JavaScript code through the search parameter. Attackers can craft malicious URLs with JavaScript payloads in the search parameter to execute code in users' browsers within the context of the affected application.