SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78238

MEDIUM · CVSS 5.4 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

SOY Gallery is vulnerable to a cross-site scripting (XSS) flaw that allows an attacker to execute arbitrary scripts in the web browser of users during the login process. This could lead to session hijacking, data theft, or other malicious actions affecting user accounts. Organizations using SOY Gallery should prioritize patching this vulnerability to protect their users from potential exploitation.

CVE
CVE-2026-78238
Severity
MEDIUM
CVSS
5.4
EPSS
0.17%

Original NVD Description

SOY Gallery contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who is logging in to the product.