PT-2026-2166 · Voltronic Power+1 · Snmp Web Pro+1

Jean-Marie Bourbon

+2

·

Published

2026-01-09

·

Updated

2026-04-22

·

CVE-2026-22192

CVSS v3.1

9.9

Critical

AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions wpDiscuz versions prior to 7.6.47
Description The software contains a stored cross-site scripting issue that permits authenticated attackers to inject malicious JavaScript. This is achieved by importing a specially crafted options file containing unescaped custom CSS field values. Attackers can provide a malicious JSON import file with script payloads within the customCss parameter. These payloads execute on every page when rendered through the options handler due to insufficient sanitization.
Recommendations Update wpDiscuz to version 7.6.47 or later.

Exploit

Fix

Missing Authentication

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-22192

Affected Products

Snmp Web Pro
Wpdiscuz