CVE-2026-106138
Cross-Site Scripting via Chart Tooltip in KendoReact
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
In Progress® KendoReact (@progress/kendo-react-charts) starting with version 1.1.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared tooltip. An attacker with low privileges who can influence a string value bound to the chart can supply HTML containing event handlers that execute JavaScript in a user's browser when the user hovers over the affected data point. Successful exploitation can compromise the confidentiality and integrity of data accessible to the affected application.
| CWE | CWE-80 |
| Vendor | progress software |
| Product | kendoreact |
| Published | Oct 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for progress software kendoreact
Be the first to know when new medium vulnerabilities affecting progress software kendoreact are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
Progress Software / KendoReact
1.1.0 < 16.2.0
References
Credits
Abhishek Nandkumar Bhaskar (Abhi-Hackz)