Stored XSS Vulnerability in Kiteworks Secure Data Forms
CVE-2026-24754

5.4MEDIUM

Key Information:

Vendor

Kiteworks

Vendor
CVE Published:
1 June 2026

What is CVE-2026-24754?

A stored XSS vulnerability exists in Kiteworks Secure Data Forms prior to version 9.3.0, which enables authenticated attackers to execute arbitrary JavaScript code in the context of other users' sessions. This could lead to unauthorized actions taken on behalf of users or expose sensitive information. It is recommended to upgrade to version 9.3.0 or later to mitigate this risk effectively.

Affected Version(s)

security-advisories < 9.3.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.