medium · CVSS v3 6.1 · CVSS v4 6.5
CVE-2026-71454
CVE-2026-71454 is a medium‑severity XSS flaw that allows attackers to inject malicious scripts into web pages. The vulnerability exists in t
Overview
CVE-2026-71454 is a medium‑severity XSS flaw that allows attackers to inject malicious scripts into web pages. The vulnerability exists in the CAPEC-63 component before version 3.0b63. It can lead to session hijacking or defacement if exploited.
Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63 allows Cross-Site Scripting (XSS). This issue affects CAPEC-63: before 3.0b63.
Impact
The flaw permits arbitrary script execution in the victim’s browser, compromising confidentiality by stealing session cookies, integrity by modifying page content, and availability if the site is used for phishing. Defenders should treat it as a risk to all users interacting with affected web pages.
Remediation
Upgrade CAPEC-63 to version 3.0b63 or later. If upgrade is not possible, sanitize all user input on the server side and enforce strict Content‑Security‑Policy headers. Monitor web logs for suspicious script injection attempts.
Risk context
Severity is medium (CVSS 6.1/6.5). No EPSS data is available, so the risk remains moderate until a patch is applied.
Affected products
- CAPEC-63 pre‑3.0b63
Scores
- Severity
- medium
- CVSS v2
- 3.5
- CVSS v3
- 6.1
- CVSS v4
- 6.5
- EPSS
- —