PT-2026-21431 · Unknown · Rymcu Forest
Xcxr
·
Published
2026-02-22
·
Updated
2026-02-25
·
CVE-2026-2946
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
rymcu forest versions prior to 0.0.6
Description
A security issue exists in rymcu forest up to version 0.0.5. The
XssUtils.replaceHtmlCode function within the src/main/java/com/rymcu/forest/util/XssUtils.java file, part of the Article Content/Comments/Portfolio component, is susceptible to cross-site scripting. Remote exploitation is possible, and details of the exploit have been publicly disclosed. The vendor was notified but did not respond.Recommendations
Update rymcu forest to version 0.0.6 or later.
As a temporary workaround, consider disabling or restricting the use of the
XssUtils.replaceHtmlCode function until a patch is available.Exploit
Fix
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rymcu Forest