AUGUST 26, 2026
Live Feed
Back to database
Case File

CVE-2026-53737

MEDIUM · CVSS 6.1 EPSS 0.16%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-06-10 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.1. It may be remotely exploitable.

CVE
CVE-2026-53737
Severity
MEDIUM
CVSS
6.1
EPSS
0.16%

Original NVD Description

Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the connected feed data can inject script that executes in an administrator's browser when the settings page loads.