PT-2026-70205 · Maalfer · Pentestify

·

CVE-2026-19434

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions maalfer Pentestify versions prior to 2.3.1
Description Authenticated users can execute arbitrary JavaScript within the application origin due to a Cross-site Scripting issue in the finding renderer. This occurs when HTML markup stored in the severity field of a finding is interpolated unescaped into class and style attributes during report rendering.
Recommendations Update maalfer Pentestify to version 2.3.1 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19434

Affected Products

Pentestify