๐Ÿ” CVE Alert

CVE-2026-55630

UNKNOWN 0.0

Kiwi TCMS: Stored XSS via javascript: URI in extra_link field (TestPlan & TestCase)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted unsanitized user input and rendered stored values verbatim, creating an opportunity for cross-site scripting. Official Docker images and unmodified Kiwi TCMS middleware send a Content-Security-Policy header that blocks inline JavaScript, making exploitation difficult in default deployments, while customized deployments that weaken those security settings may remain vulnerable. Version 16.1 properly sanitizes both fields and resets existing database records that do not validate to null. This issue is fixed in version 16.1.

CWE CWE-79
Vendor kiwitcms
Product kiwi
Published Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for kiwitcms kiwi

Be the first to know when new unknown vulnerabilities affecting kiwitcms kiwi are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
None

Affected Versions

kiwitcms / Kiwi
< 16.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kiwitcms/Kiwi/security/advisories/GHSA-473p-56xx-vg67 github.com: https://github.com/kiwitcms/Kiwi/commit/1c2ecc8485faeefd84a526314a0a60d132fbbc09 github.com: https://github.com/kiwitcms/Kiwi/commit/d5d36e74cf9333cb37e3a8743b22b74dfa9a0139 github.com: https://github.com/kiwitcms/Kiwi/releases/tag/v16.1