PatchSiren

kkFileView CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM kkFileView CVE published 2026-09-16

CVE-2026-88593

kkFileView 5.0.0 through 5.0.2 is vulnerable to reflected XSS attacks via the /onlinePreview endpoint. The OnlinePreviewController passes user-controlled page and kkagent request parameters to FreeMarker templates without sanitization, allowing for potential security bypass or data tampering. Defenders should prioritize verifying exposure and implementing input sanitization to prevent XSS attacks. This vu [truncated]