SEPTEMBER 24, 2026
Live Feed
Back to database
Case File

CVE-2026-54219

UNKNOWN · CVSS N/A EPSS 0.29%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-06-18 · Last synced 2026-08-04

CyberRota Analysis

This vulnerability has an unknown severity rating. It affects Java.

CVE
CVE-2026-54219
Severity
UNKNOWN
CVSS
N/A
EPSS
0.29%
Java

Original NVD Description

UBB.threads is vulnerable to Stored XSS via user posts and user profile fields. The application fails to properly sanitize user input, allowing low privileged attackers to inject arbitrary JavaScript that executes in a victim's browser upon viewing. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 7.7.5 but may also affect other versions.