DOM-Based Cross-Site Scripting Vulnerability in IP Reputation Checker by th30d4y
CVE-2026-41575

6.1MEDIUM

Key Information:

Vendor

Th30d4y

Status
Vendor
CVE Published:
8 May 2026

What is CVE-2026-41575?

A DOM-Based Cross-Site Scripting vulnerability has been found in the IP Reputation Checker application developed by th30d4y. This issue arises from unsanitized user input being rendered directly in the browser, which can allow attackers to inject and execute arbitrary JavaScript code. Users are strongly advised to update to version 2.0.1 or later to mitigate this risk. Full details on the vulnerability and its resolution can be found in the official advisory.

Affected Version(s)

IP >= 1.0.1, < 2.0.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.