Cross-site Scripting Vulnerability in Pentestify by maalfer
CVE-2026-19744
5.1MEDIUM
What is CVE-2026-19744?
A Cross-site Scripting vulnerability exists in the Markdown renderer of Pentestify, affecting versions prior to 2.3.2. This flaw allows authenticated users to embed arbitrary JavaScript in the application through Markdown links containing unescaped double quotes. The lack of proper sanitization during the rendering process permits the execution of malicious scripts, potentially compromising the integrity of the application and its users. Prompt upgrading to version 2.3.2 or later is recommended to mitigate this risk.
Affected Version(s)
Pentestify 0 < 2.3.2
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jaime RamĂrez
XoĂĄn M. Otero Jorge
Secur0 CNA
Mario Ălvarez FernĂĄndez
