๐Ÿ” CVE Alert

CVE-2026-27787

MEDIUM 5.4
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
9th

Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.

Vendor icz corporation
Product matcha sns
Published Apr 8, 2026
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for icz corporation matcha sns

Be the first to know when new medium vulnerabilities affecting icz corporation matcha sns are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected Versions

ICZ Corporation / MATCHA SNS
1.3.9 and earlier

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
oss.icz.co.jp: https://oss.icz.co.jp/news/?p=1388 jvn.jp: https://jvn.jp/en/jp/JVN33581068/