Stored Cross-site Scripting Vulnerability in maalfer Pentestify
CVE-2026-59238

6.9MEDIUM

Key Information:

Vendor

Maalfer

Vendor
CVE Published:
20 July 2026

What is CVE-2026-59238?

A vulnerability in maalfer Pentestify prior to version 1.1.0 allows authenticated attackers to exploit stored cross-site scripting. By injecting malicious JavaScript into the client-side report rendering functions, an attacker can manipulate the display of findings images or client logos. This unsanitized data is then rendered into an src attribute, enabling the execution of arbitrary JavaScript in the browsers of users who access affected reports, potentially compromising sensitive information and user session data. Immediate action is recommended to secure your application.

Affected Version(s)

Pentestify 0 < 1.1.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marcos GarcĂ­a (s3ntinl)
Mario Álvarez Fernåndez
XoĂĄn M. Otero Jorge
Secur0 CNA
.