PatchSiren

maalfer CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM maalfer CVE published 2026-07-20

CVE-2026-59238

CVE-2026-59238 is a Stored Cross-site Scripting (XSS) vulnerability in the client-side report rendering functions of Pentestify before version 1.1.0. The vulnerability allows a remote, authenticated attacker to execute arbitrary JavaScript in the browser of any user who views an affected report. The payload can be stored in a finding's images array or a report's client_logo array, which is then interpolat [truncated]