PatchSiren

SQLView CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM SQLView CVE published 2026-10-08

CVE-2026-89191

A stored cross-site scripting vulnerability exists in SQLView KRIS's Workflow Template feature. An attacker with administrative access can inject and store malicious scripts in the 'template name' field, which are then rendered in 'onclick' attributes on the main dashboard without proper sanitization. This allows the scripts to execute in the browsers of affected users.