CyberRota Analysis
AI-GeneratedBrave Popup Builder versions up to 0.8.5 are vulnerable due to improper handling of UTM query parameters, which are reflected in popup form HTML without adequate escaping. This flaw could lead to cross-site scripting (XSS) attacks, potentially allowing an attacker to execute malicious scripts in the context of the user’s session. Developers and organizations utilizing this plugin should prioritize remediation to mitigate the risk of exploitation.
CVE
CVE-2026-77115
Severity
HIGH
CVSS
7.1
EPSS
0.15%
Original NVD Description
Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.