๐Ÿ” CVE Alert

CVE-2026-3877

UNKNOWN 0.0

Reflected Cross-Site Scripting in Dashboard Search

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A reflected cross-site scripting (XSS) vulnerability in the dashboard search functionality of the VertiGIS FM solution allows attackers to craft a malicious URL, that if visited by an authenticated victim, will execute arbitrary JavaScript in the victim's context. Such a URL could be delivered through various means, for instance, by sending a link or by tricking victims to visit a page crafted by the attacker.

CWE CWE-79
Vendor vertigis
Product vertigis fm
Published Apr 1, 2026
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for vertigis vertigis fm

Be the first to know when new unknown vulnerabilities affecting vertigis vertigis fm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

VertiGIS / VertiGIS FM
0 < 10.13.403

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
redguard.ch: https://www.redguard.ch/blog/2026/04/01/advisory-vertigis-vertigisfm/

Credits

Benjamin Faller, Redguard AG Andreas Pfefferle, Redguard AG