Cross-Site Scripting Vulnerability in Movary Web Application
CVE-2026-23839

9.3CRITICAL

Key Information:

Vendor

Leepeuker

Status
Vendor
CVE Published:
19 January 2026

What is CVE-2026-23839?

The Movary web application, designed for users to track and rate their movie watch history, is susceptible to a cross-site scripting (XSS) vulnerability. Attackers can exploit this issue due to insufficient input validation in the ?categoryUpdated= parameter. This vulnerability allows for the execution of arbitrary JavaScript in users' browsers, posing significant security risks. Users are encouraged to upgrade to Movary version 0.70.0 or later, where this issue has been rectified.

Affected Version(s)

movary < 0.70.0

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.