PT-2026-3259 · Pem · Pem

Published

2026-01-16

·

Updated

2026-02-10

·

CVE-2026-0949

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions PEM versions prior to 9.8.1
Description PEM versions before 9.8.1 have a stored Cross-site Scripting (XSS) issue. A user with access to the Manage Charts menu can inject arbitrary JavaScript when creating a new chart. This JavaScript is then executed when any user accesses the chart. Access to the Manage Charts menu is, by default, limited to the superuser and users with pem admin or pem super admin privileges.
Recommendations Update to PEM version 9.8.1 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-0949

Affected Products

Pem