Stored XSS Vulnerability in Kiteworks Secure Data Forms
CVE-2026-24754
5.4MEDIUM
What is CVE-2026-24754?
A stored XSS vulnerability exists in Kiteworks Secure Data Forms prior to version 9.3.0, which enables authenticated attackers to execute arbitrary JavaScript code in the context of other users' sessions. This could lead to unauthorized actions taken on behalf of users or expose sensitive information. It is recommended to upgrade to version 9.3.0 or later to mitigate this risk effectively.
Affected Version(s)
security-advisories < 9.3.0
