Cross-Site Scripting Vulnerability in myCred Plugin by Saad Iqbal
CVE-2026-27440
6.5MEDIUM
What is CVE-2026-27440?
The myCred plugin developed by Saad Iqbal has a vulnerability that allows for stored cross-site scripting (XSS) due to improper neutralization of input during web page generation. This flaw can potentially lead to the execution of malicious scripts in the context of authenticated users, increasing the risk of unauthorized actions on behalf of the affected users. Users of myCred versions up to 2.9.7.6 are at risk and should take immediate action to mitigate this vulnerability.
Affected Version(s)
myCred 0 <= 2.9.7.6