rootpwn

medium · CVSS v3 6.1 · CVSS v4 6.5

CVE-2026-71454

CVE-2026-71454 is a medium‑severity XSS flaw that allows attackers to inject malicious scripts into web pages. The vulnerability exists in t

Overview

CVE-2026-71454 is a medium‑severity XSS flaw that allows attackers to inject malicious scripts into web pages. The vulnerability exists in the CAPEC-63 component before version 3.0b63. It can lead to session hijacking or defacement if exploited.

Description

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63 allows Cross-Site Scripting (XSS). This issue affects CAPEC-63: before 3.0b63.

Impact

The flaw permits arbitrary script execution in the victim’s browser, compromising confidentiality by stealing session cookies, integrity by modifying page content, and availability if the site is used for phishing. Defenders should treat it as a risk to all users interacting with affected web pages.

Remediation

Upgrade CAPEC-63 to version 3.0b63 or later. If upgrade is not possible, sanitize all user input on the server side and enforce strict Content‑Security‑Policy headers. Monitor web logs for suspicious script injection attempts.

Risk context

Severity is medium (CVSS 6.1/6.5). No EPSS data is available, so the risk remains moderate until a patch is applied.

Affected products

  • CAPEC-63 pre‑3.0b63

Scores

Severity
medium
CVSS v2
3.5
CVSS v3
6.1
CVSS v4
6.5
EPSS
—

xss web input-validation medium CAPEC-63

← All CVEs