CVE-2026-19988
Alaev SEO Tools Extension Popup UI popup.html addDiv cross site scripting
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was detected in Alaev SEO Tools Extension up to 1.0.10 on Chrome. This impacts the function addDiv of the file src/popup.html of the component Popup UI. Performing a manipulation results in basic cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
| CWE | CWE-80 CWE-74 |
| Vendor | alaev |
| Product | seo tools extension |
| Published | Aug 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for alaev seo tools extension
Be the first to know when new medium vulnerabilities affecting alaev seo tools extension are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Alaev / SEO Tools Extension
1.0.0 1.0.1 1.0.2 1.0.3 1.0.4 1.0.5 1.0.6 1.0.7 1.0.8 1.0.9 1.0.10
References
vuldb.com: https://vuldb.com/vuln/391192 vuldb.com: https://vuldb.com/vuln/391192/cti vuldb.com: https://vuldb.com/cve/CVE-2026-19988 vuldb.com: https://vuldb.com/submit/873939 github.com: https://github.com/xryj920/chrome_extensions/blob/main/Alaev%20%26%20Co%20Alaev%20SEO%20Tools%201.0.10%20allows%20extension%20popup%20UI%20injection%20through%20unsanitized%20page%20SEO%20fields
Credits
๐ DRXYJ (VulDB User) VulDB CNA Team