Cross-Site Scripting Vulnerability in Pentestify by CCYL
CVE-2026-19434

5.1MEDIUM

Key Information:

Vendor

Maalfer

Vendor
CVE Published:
11 August 2026

What is CVE-2026-19434?

A Cross-Site Scripting vulnerability exists in the finding renderer of Pentestify prior to version 2.3.1. This issue allows authenticated users to inject arbitrary JavaScript into the application through HTML markup stored in a finding's severity field. The frontend renders this unsafe content unescaped into class and style attributes, leading to potential execution of malicious scripts within the application context, thereby compromising the integrity and security of user data.

Affected Version(s)

Pentestify 0 < 2.3.1

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marcos GarcĂ­a (s3ntinl)
Cristian FernĂĄndez Cornejo
XoĂĄn M. Otero Jorge
Secur0 CNA
Mario Álvarez Fernåndez
.