๐Ÿ” CVE Alert

CVE-2026-35466

MEDIUM 6.1

Stored XSS via unsanitized input from remote service

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
8th

XSS vulnerability in cveInterface.js allows for inject HTML to be passed to display, as cveInterface trusts input from CVE API services

CWE CWE-79
Vendor cert/cc
Product cveclient/cveinterface.js
Published Apr 2, 2026
Last Updated Apr 3, 2026
Stay Ahead of the Next One

Get instant alerts for cert/cc cveclient/cveinterface.js

Be the first to know when new medium vulnerabilities affecting cert/cc cveclient/cveinterface.js are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

CERT/CC / cveClient/cveInterface.js
0 < 1.0.24

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/CERTCC/cveClient/pull/37 github.com: https://github.com/CERTCC/cveClient

Credits

Jerry Gamblin (https://github.com/jgamblin)