CVE-2026-85229
Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking Booster UI. This issue affects Apache SkyWalking UI : from 10.2.0 through 10.4.0. Users are recommended to upgrade to Horizon UI 1.0.0, which fixes the issue.
| CWE | CWE-79 |
| Vendor | apache software foundation |
| Product | apache skywalking |
| Published | Sep 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache skywalking
Be the first to know when new unknown vulnerabilities affecting apache software foundation apache skywalking are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Apache Software Foundation / Apache SkyWalking
10.2.0 ≤ 10.4.0
References
Credits
🔍 n0mi1k