🔐 CVE Alert

CVE-2026-6088

UNKNOWN 0.0

Stored Cross-Site Scripting in StockAgile by Novadigits technologies

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/categories' that allow the injection and persistence of malicious JavaScript code through parameters such as ‘code’, ‘name’, and other text fields. The scripts that are entered are not filtered or validated correctly before being displayed on the web panel that authenticated users can access. Exploiting this vulnerability could allow a remote, previously authenticated attacker to execute arbitrary JavaScript code.

CWE CWE-79
Vendor novadigits technologies
Product stockagile
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for novadigits technologies stockagile

Be the first to know when new unknown vulnerabilities affecting novadigits technologies stockagile are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Novadigits technologies / StockAgile
0 < 25/09/2026

References

NVD ↗ CVE.org ↗ EPSS Data ↗
incibe.es: https://www.incibe.es/en/incibe-cert/notices/aviso/stored-cross-site-scripting-stockagile-novadigits-technologies

Credits

Miguel Jiménez Cámara