SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-90528

LOW · CVSS 3.5

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

A cross-site scripting vulnerability exists in the Form Write View component of TDuckApp tduck-platform versions up to 5.3, allowing remote attackers to manipulate the submitShowCustomPageContent argument. This flaw could lead to unauthorized script execution in the context of the user's session. Organizations using affected versions should prioritize remediation to mitigate potential exploitation risks.

CVE
CVE-2026-90528
Severity
LOW
CVSS
3.5
EPSS
N/A

Original NVD Description

A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality of the file tduck-front/src/views/form/write/index.vue of the component Form Write View. This manipulation of the argument submitShowCustomPageContent causes cross site scripting. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.