PT-2026-29449 · Welovemedia · Ffmate

Vuldb

·

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2026-5254

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions welovemedia FFmate versions up to 2.0.15
Description A security issue exists in welovemedia FFmate up to version 2.0.15 related to cross site scripting. The issue is located in the file /ui/app/components/AppJsonTreeView.vue within the Webhook Handler component. The manipulation of some unknown functionality leads to cross site scripting and can be initiated remotely. The exploit has been publicly disclosed.
Recommendations Update to a version later than 2.0.15.

Exploit

Fix

Code Injection

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-5254

Affected Products

Ffmate