🔐 CVE Alert

CVE-2026-59238

UNKNOWN 0.0

Stored XSS in Pentestify via unsanitized finding images and report client logo

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Stored Cross-site Scripting (CWE-79) in the client-side report rendering functions (renderPreview, renderEditor, renderAuditData in js/app.js) in maalfer Pentestify before 1.1.0 allows a remote, authenticated attacker to execute arbitrary JavaScript in the browser of any user who views an affected report via a payload stored in a finding's images array or a report's client_logo array, which is interpolated into an <img> src attribute without escaping.

CWE CWE-79
Vendor maalfer
Product pentestify
Published Jul 20, 2026
Last Updated Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for maalfer pentestify

Be the first to know when new unknown vulnerabilities affecting maalfer pentestify are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

maalfer / Pentestify
0 < 1.1.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/maalfer/pentestify/commit/a058a22b42c6311895622645265df79a60265b1d secur0.com: https://secur0.com/en/cna/cve-list/cve-2026-59238-stored-xss-in-pentestify-via-unsanitized-finding-images-and-report-client-logo

Credits

Marcos García (s3ntinl) Mario Álvarez Fernández Xoán M. Otero Jorge Secur0 CNA