PT-2026-79762 · WordPress · Brave Popup Builder

·

CVE-2026-77115

·

Published

2026-08-23

·

Updated

2026-08-23

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Brave Popup Builder versions prior to 0.8.6
Description Brave Popup Builder reflects UTM query parameters into the popup form HTML without proper escaping, leading to Reflected Cross-Site Scripting (XSS). This occurs when the application takes user-supplied input from UTM parameters and includes it in the HTML response without sanitization.
Recommendations Update Brave Popup Builder to version 0.8.6 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77115

Affected Products

Brave Popup Builder