PatchSiren

factionsecurity CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH factionsecurity CVE published 2026-05-26

CVE-2026-44669

FACTION, a penetration testing report generation and collaboration framework, contains a stored cross-site scripting (XSS) vulnerability in versions prior to 1.8.3. The flaw exists in assessment file preview flows where user-supplied attachment filenames are persisted to the server and subsequently rendered into HTML and attribute contexts without proper output encoding. Because the malicious payload is s [truncated]

HIGH factionsecurity CVE published 2026-05-26

CVE-2026-44667

FACTION PenTesting Report Generation and Collaboration Framework versions prior to 1.8.3 contain a stored cross-site scripting (XSS) vulnerability in remediation verification file preview flows. User-supplied attachment filenames are persisted server-side and subsequently rendered into HTML and attribute contexts without proper output encoding. This allows attacker-controlled JavaScript to execute in brow [truncated]