SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-77115

HIGH · CVSS 7.1 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-23 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Brave Popup Builder versions up to 0.8.5 are vulnerable due to improper handling of UTM query parameters, which are reflected in popup form HTML without adequate escaping. This flaw could lead to cross-site scripting (XSS) attacks, potentially allowing an attacker to execute malicious scripts in the context of the user’s session. Developers and organizations utilizing this plugin should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-77115
Severity
HIGH
CVSS
7.1
EPSS
0.15%

Original NVD Description

Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.