CVE-2026-106139
Cross-Site Scripting via Chart Tooltip in Kendo UI for Vue
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
In Progress® Kendo UI for Vue (@progress/kendo-vue-charts) starting with version 2.5.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared tooltip. An attacker with low privileges who can influence a string value bound to the chart can supply HTML containing event handlers that execute JavaScript in a user's browser when the user hovers over the affected data point. Successful exploitation can compromise the confidentiality and integrity of data accessible to the affected application.
| CWE | CWE-80 |
| Vendor | progress software |
| Product | kendo ui for vue |
| Published | Oct 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for progress software kendo ui for vue
Be the first to know when new medium vulnerabilities affecting progress software kendo ui for vue are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
Progress Software / Kendo UI for Vue
2.5.0 < 10.1.0
References
Credits
Abhishek Nandkumar Bhaskar (Abhi-Hackz)