PatchSiren

ICZ CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Icz CVE published 2026-04-08

CVE-2026-27787

A cross-site scripting vulnerability was found in MATCHA SNS version 1.3.9 and earlier. Successful exploitation could allow an attacker to execute an arbitrary script on the web browser of a user who accessed the website using the product. This type of vulnerability typically involves injecting malicious scripts into web pages viewed by other users. Users should update to a patched version if available an [truncated]

HIGH ICZ CVE published 2026-04-08

CVE-2026-24913

A SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or altered by a user who can log in to the product. This vulnerability has been rated with a CVSS score of 8.7 and a severity of HIGH. The vulnerability allows a logged-in user to potentially obtain or alter information stored in the database. The [truncated]