CVE-2026-41031
A Stored Cross-Site Scripting (XSS) vulnerability occurs in Vinna Process Monitor
CVSS Score
8.7
EPSS Score
0.0%
EPSS Percentile
14th
A Stored Cross-Site Scripting vulnerability in Vinna Process Monitor Version 4.0 Service Pack 1 (Build 63255) allows an authenticated remote attacker with low privileges to inject malicious JavaScript code into the application. This enables attackers to steal administrative access tokens and session credentials.
| CWE | CWE-79 |
| Vendor | skilja gmbh |
| Product | vinna process monitor |
| Published | Jun 9, 2026 |
| Last Updated | Jun 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for skilja gmbh vinna process monitor
Be the first to know when new high vulnerabilities affecting skilja gmbh vinna process monitor are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
Skilja GmbH / Vinna Process Monitor
3.1.2 < 4.0.6
References
Credits
Michał Bartoszuk and Maciej Włodarczyk @STM Cyber