🔐 CVE Alert

CVE-2026-19744

UNKNOWN 0.0

Stored Cross-site Scripting in Pentestify Markdown renderer via unescaped quotes

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute arbitrary JavaScript in the application origin via a Markdown link whose URL contains a double quote, which closes the anchor's href attribute because the renderer's sanitization step does not escape quotes

CWE CWE-79
Vendor maalfer
Product pentestify
Published Aug 13, 2026
Stay Ahead of the Next One

Get instant alerts for maalfer pentestify

Be the first to know when new unknown vulnerabilities affecting maalfer pentestify are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

maalfer / Pentestify
0 < 2.3.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/ccyl13/Pentestify/commit/272f7d6033fd93fbc858835f55d616157041f123 github.com: https://github.com/ccyl13/Pentestify/releases/tag/v2.3.2 secur0.com: https://secur0.com/en/cna/cve-list/cve-2026-19744-stored-xss-in-pentestify-markdown-renderer-via-unescaped-quotes

Credits

Jaime Ramírez Xoán M. Otero Jorge Secur0 CNA Mario Álvarez Fernández