PT-2026-45954 · Undefined · Undefined

Published

2026-06-03

·

Updated

2026-06-03

·

CVE-2026-36748

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-36748

Affected Products

Undefined