Cross-site Scripting Vulnerability in Custom Query Blocks by Ronald Huereca
CVE-2026-39575
6.5MEDIUM
What is CVE-2026-39575?
The vulnerability within Custom Query Blocks by Ronald Huereca is characterized by improper neutralization of user inputs during web page generation, resulting in a DOM-Based XSS issue. This flaw allows attackers to execute scripts in the context of the user's browser. Affected versions range from n/a up to 5.5.0, making it crucial for users and developers to implement corrective measures to safeguard against potential exploitation.
Affected Version(s)
Custom Query Blocks 0 <= 5.5.0