The CVE-2026-75872 record details an HTML injection vulnerability in the public subscription form of MailerUp before version 1.1.3. This vulnerability allows unauthenticated remote attackers to inject arbitrary HTML content into the double opt-in verification email by manipulating the first_name field of the subscription request. Organizations using MailerUp for email subscriptions, especially those with [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T16:17:59.903Z and has not been modified since then. The NVD entry is currently Deferred. The CVE-2026-19744 vulnerability is a Cross-site Scripting issue in the Markdown renderer of Pentestify, a tool used for penetration testing. Authenticated users can execute arbitrary JavaScript in the applic [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T14:16:55.583Z and has not been modified since then. CVE-2026-19716 is a Stored Cross-site Scripting (CWE-79) vulnerability in the user management component of Pentestify. An authenticated attacker can inject arbitrary JavaScript into the browser session of another authenticated user by crafting a [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T14:17:13.433Z and has not been modified since then. The vulnerability is a cross-site scripting (XSS) issue in the finding renderer of Pentestify before version 2.3.1. Authenticated users can inject arbitrary JavaScript via HTML markup stored in a finding's severity field. The frontend interpolat [truncated]
CVE-2026-59238 is a Stored Cross-site Scripting (XSS) vulnerability in the client-side report rendering functions of Pentestify before version 1.1.0. The vulnerability allows a remote, authenticated attacker to execute arbitrary JavaScript in the browser of any user who views an affected report. The payload can be stored in a finding's images array or a report's client_logo array, which is then interpolat [truncated]