PatchSiren

XMLRPC-C CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH XMLRPC-C CVE published 2026-07-27

CVE-2026-15928

CVE-2026-15928 is a reflected cross-site scripting (XSS) vulnerability affecting XMLRPC-C Library versions 1.07 through 1.67.01 in the error page component. The vulnerability has a CVSS score of 8.2 and is classified as HIGH severity. This type of vulnerability allows an attacker to inject malicious scripts into the error page, potentially leading to unauthorized actions or data breaches. Developers and a [truncated]