PT-2026-57053 · Myems · Myems

·

CVE-2026-15321

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v2.0

3.3

Low

VectorAV:N/AC:L/Au:M/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions MyEMS versions prior to 6.5.0
Description An issue exists in the Admin Backend component within the on post() function of the myems-api/core/svg.py file. Remote attackers can trigger cross-site scripting (XSS)—a technique used to inject malicious scripts into web pages viewed by other users—by manipulating the new values['data'] variable.
Recommendations Upgrade to version 6.5.0.

Exploit

Fix

Code Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15321

Affected Products

Myems