PT-2026-45555 · Kiteworks · Kiteworks

Icare

+2

·

Published

2026-06-01

·

Updated

2026-06-03

·

CVE-2026-24751

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kiteworks versions prior to 9.3.0
Description A reflected Cross-Site Scripting (XSS) issue in Kiteworks Secure Data Forms allows an external attacker to trick a user into executing arbitrary JavaScript code. Cross-Site Scripting is a flaw where malicious scripts are injected into otherwise trusted websites.
Recommendations Update to version 9.3.0 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-24751

Affected Products

Kiteworks