MEDIUM
SQLView
CVE published 2026-10-08
CVE-2026-89191
A stored cross-site scripting vulnerability exists in SQLView KRIS's Workflow Template feature. An attacker with administrative access can inject and store malicious scripts in the 'template name' field, which are then rendered in 'onclick' attributes on the main dashboard without proper sanitization. This allows the scripts to execute in the browsers of affected users.