CVE-2026-19744
Stored Cross-site Scripting in Pentestify Markdown renderer via unescaped quotes
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute arbitrary JavaScript in the application origin via a Markdown link whose URL contains a double quote, which closes the anchor's href attribute because the renderer's sanitization step does not escape quotes
| CWE | CWE-79 |
| Vendor | maalfer |
| Product | pentestify |
| Published | Aug 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for maalfer pentestify
Be the first to know when new unknown vulnerabilities affecting maalfer pentestify are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
maalfer / Pentestify
0 < 2.3.2
References
Credits
Jaime Ramírez Xoán M. Otero Jorge Secur0 CNA Mario Álvarez Fernández