PatchSiren

Novadigits technologies CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Novadigits technologies CVE published 2026-09-25

CVE-2026-6088

A stored Cross-Site Scripting (XSS) vulnerability exists in the StockAgile API and management panel, specifically in the '/inventory/configuration/categories' REST endpoint. This allows for the injection and persistence of malicious JavaScript code through parameters such as 'code', 'name', and other text fields. The scripts entered are not filtered or validated correctly before being displayed on the web [truncated]

MEDIUM Novadigits technologies CVE published 2026-09-25

CVE-2026-6087

A stored Cross-Site Scripting (XSS) vulnerability exists in the StockAgile API and management panel, specifically in the REST endpoint '/inventory/configuration/categories'. This allows for the injection and persistence of malicious JavaScript code through parameters such as 'code', 'name', and other text fields. The scripts entered are not filtered or validated correctly before being displayed on the web [truncated]

MEDIUM Novadigits technologies CVE published 2026-09-25

CVE-2026-6086

A stored Cross-Site Scripting (XSS) vulnerability exists in the StockAgile API and management panel, specifically in the REST endpoint '/inventory/configuration/serial-number-types'. This allows the injection and persistence of malicious JavaScript code through parameters such as 'code', 'name', and other text fields. The scripts entered are not filtered or validated correctly before being displayed on th [truncated]

MEDIUM Novadigits technologies CVE published 2026-09-25

CVE-2026-6085

A stored Cross-Site Scripting (XSS) vulnerability exists in the StockAgile API and management panel, specifically in the REST endpoint '/inventory/configuration/serial-number-types'. This allows the injection and persistence of malicious JavaScript code through parameters such as 'code', 'name', and other text fields. The scripts entered are not filtered or validated correctly before being displayed on th [truncated]

MEDIUM Novadigits technologies CVE published 2026-09-25

CVE-2026-6084

A stored Cross-Site Scripting (XSS) vulnerability exists in the StockAgile API and management panel, specifically in the '/inventory/configuration/variants' REST endpoint. This allows for the injection and persistence of malicious JavaScript code through parameters such as 'code', 'name', and other text fields. The scripts entered are not filtered or validated correctly before being displayed on the web p [truncated]

MEDIUM Novadigits technologies CVE published 2026-09-25

CVE-2026-6083

A stored Cross-Site Scripting (XSS) vulnerability exists in the StockAgile API and management panel, specifically in the '/inventory/configuration/pricing-tiers' REST endpoint. This allows for the injection and persistence of malicious JavaScript code through parameters such as 'code', 'name', and other text fields. The scripts entered are not filtered or validated correctly before being displayed on the [truncated]

MEDIUM Novadigits technologies CVE published 2026-09-25

CVE-2026-6082

A Stored Cross-Site Scripting (XSS) vulnerability exists in the StockAgile API and management panel, specifically in the REST endpoint '/inventory/configuration/payment-methods'. This allows the injection and persistence of malicious JavaScript code through parameters such as 'code', 'name', and other text fields. The scripts entered are not filtered or validated correctly before being displayed on the we [truncated]