๐Ÿ” CVE Alert

CVE-2026-19988

MEDIUM 4.3

Alaev SEO Tools Extension Popup UI popup.html addDiv cross site scripting

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was detected in Alaev SEO Tools Extension up to 1.0.10 on Chrome. This impacts the function addDiv of the file src/popup.html of the component Popup UI. Performing a manipulation results in basic cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CWE CWE-80 CWE-74
Vendor alaev
Product seo tools extension
Published Aug 17, 2026
Stay Ahead of the Next One

Get instant alerts for alaev seo tools extension

Be the first to know when new medium vulnerabilities affecting alaev seo tools extension are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Alaev / SEO Tools Extension
1.0.0 1.0.1 1.0.2 1.0.3 1.0.4 1.0.5 1.0.6 1.0.7 1.0.8 1.0.9 1.0.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/391192 vuldb.com: https://vuldb.com/vuln/391192/cti vuldb.com: https://vuldb.com/cve/CVE-2026-19988 vuldb.com: https://vuldb.com/submit/873939 github.com: https://github.com/xryj920/chrome_extensions/blob/main/Alaev%20%26%20Co%20Alaev%20SEO%20Tools%201.0.10%20allows%20extension%20popup%20UI%20injection%20through%20unsanitized%20page%20SEO%20fields

Credits

๐Ÿ” DRXYJ (VulDB User) VulDB CNA Team