CVE-2026-19434
Stored Cross-site Scripting in Pentestify finding severity field
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the application origin via HTML markup stored in a finding's severity field, which the frontend interpolates unescaped into class and style attributes when rendering the report.
| CWE | CWE-79 |
| Vendor | maalfer |
| Product | pentestify |
| Published | Aug 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for maalfer pentestify
Be the first to know when new unknown vulnerabilities affecting maalfer pentestify are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
maalfer / Pentestify
0 < 2.3.1
References
Credits
Marcos García (s3ntinl) Cristian Fernández Cornejo Xoán M. Otero Jorge Secur0 CNA Mario Álvarez Fernández