Cross-site Scripting Vulnerability in Pentestify by maalfer
CVE-2026-19744

5.1MEDIUM

Key Information:

Vendor

Maalfer

Vendor
CVE Published:
13 August 2026

What is CVE-2026-19744?

A Cross-site Scripting vulnerability exists in the Markdown renderer of Pentestify, affecting versions prior to 2.3.2. This flaw allows authenticated users to embed arbitrary JavaScript in the application through Markdown links containing unescaped double quotes. The lack of proper sanitization during the rendering process permits the execution of malicious scripts, potentially compromising the integrity of the application and its users. Prompt upgrading to version 2.3.2 or later is recommended to mitigate this risk.

Affected Version(s)

Pentestify 0 < 2.3.2

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jaime RamĂ­rez
XoĂĄn M. Otero Jorge
Secur0 CNA
Mario Álvarez Fernåndez
.