Stored Cross-Site Scripting Vulnerability in Vinna Process Monitor by Skilja
CVE-2026-41031

9.3CRITICAL

Key Information:

Vendor
CVE Published:
9 June 2026

What is CVE-2026-41031?

The Vinna Process Monitor Version 4.0 Service Pack 1 (Build 63255) has a vulnerability that allows an authenticated remote attacker with low privileges to insert malicious JavaScript code into the application. This vulnerability exposes the application's users to the risk of losing sensitive administrative access tokens and session credentials, which could lead to unauthorized access and exploitation of the system.

Affected Version(s)

Vinna Process Monitor 3.1.2 < 4.0.6

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michał Bartoszuk and Maciej Włodarczyk @STM Cyber
.