Persistent Script Injection Vulnerability in WhatsUp Gold by Progress
CVE-2026-65937
8HIGH
What is CVE-2026-65937?
WhatsUp Gold versions released prior to 2026.0.2 are vulnerable to a persistent script injection flaw. An authenticated attacker can exploit this vulnerability to bypass frontend controls, allowing them to inject malicious script content that persists within the application. This can lead to severe consequences, including unauthorized actions and data manipulation, leveraging user trust in legitimate web application functionality.
Affected Version(s)
WhatsUp Gold Windows 0 < 26.0.2