PT-2026-56086 · Kiwi Tcms · Kiwi Tcms

CVE-2026-55630

·

Published

2026-07-06

·

Updated

2026-07-13

CVSS v3.1

0.0

None

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kiwi TCMS versions prior to 16.1
Description User input in the TestCase.extra link and TestPlan.extra link fields is not sanitized and is rendered verbatim, allowing for cross-site scripting (XSS), a technique where malicious scripts are injected into trusted websites. Deployments using official Docker images or unmodified middleware utilize a Content-Security-Policy header that blocks inline JavaScript execution, mitigating the risk. However, customized deployments with modified security settings remain susceptible.
Recommendations Update to version 16.1.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55630
GHSA-473P-56XX-VG67
PYSEC-2026-2551

Affected Products

Kiwi Tcms