Gotohttp · Gotohttp · CVE-2026-13536
**Name of the Vulnerable Software and Affected Versions**
GotoHTTP versions prior to 10.3
**Description**
Remote attackers can initiate cross site scripting by manipulating the `sn` argument during the processing of the `/reg.12x` file. Cross site scripting is a technique where malicious scripts are injected into trusted websites.
**Recommendations**
Update to version 10.3 or later.
As a temporary mitigation, restrict access to the `/reg.12x` file.