PT-2026-2166 · Voltronic Power+1 · Snmp Web Pro+1

Jean-Marie Bourbon

+2

·

Publicado

2026-01-09

·

Atualizado

2026-04-22

·

CVE-2026-22192

CVSS v3.1

9.9

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions wpDiscuz versions prior to 7.6.47
Description The software contains a stored cross-site scripting issue that permits authenticated attackers to inject malicious JavaScript. This is achieved by importing a specially crafted options file containing unescaped custom CSS field values. Attackers can provide a malicious JSON import file with script payloads within the customCss parameter. These payloads execute on every page when rendered through the options handler due to insufficient sanitization.
Recommendations Update wpDiscuz to version 7.6.47 or later.

Exploit

Correção

XSS

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-22192

Produtos afetados

Snmp Web Pro
Wpdiscuz