CyberRota Analysis
AI-GeneratedThe vulnerability allows unauthenticated cross-site scripting (XSS) in Notification for Telegram versions 3.5.2 and earlier, enabling attackers to execute arbitrary scripts in the context of the user's session. This could lead to data theft, session hijacking, or other malicious actions. Organizations using affected versions should prioritize remediation to protect user data and maintain application integrity.
CVE
CVE-2026-93514
Severity
HIGH
CVSS
7.1
EPSS
0.18%
Original NVD Description
Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions.