🔐 CVE Alert

CVE-2026-5010

UNKNOWN 0.0

Reflected Cross-Site Scripting (XSS) in Sanoma’s Clickedu

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A reflected Cross-Site Scripting (XSS) vulnerability has been discovered in Clickedu. This vulnerability allows an attacker to execute JavaScript code in the victim’s browser by sending them a malicious URL using the endpoint “/user.php/”. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on the user’s behalf.

CWE CWE-79
Vendor sanoma
Product clickedu
Published Mar 27, 2026
Last Updated Mar 27, 2026
Stay Ahead of the Next One

Get instant alerts for sanoma clickedu

Be the first to know when new unknown vulnerabilities affecting sanoma clickedu are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Sanoma / Clickedu
0 < 5.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
incibe.es: https://www.incibe.es/en/incibe-cert/notices/aviso/reflected-cross-site-scripting-xss-sanomas-clickedu-0

Credits

Gonzalo Aguilar García (6h4ack)