No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 01 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Oct 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kiteworks
Kiteworks core |
|
| Vendors & Products |
Kiteworks
Kiteworks core |
Wed, 30 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could allow an authenticated user to store crafted content that executes arbitrary JavaScript in another user's authenticated session when they preview shared content. This could potentially lead to session compromise and account takeover. | |
| Title | Kiteworks Core stored XSS | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-10-01T15:28:06.066Z
Reserved: 2026-09-28T17:39:13.560Z
Link: CVE-2026-102092
Updated: 2026-10-01T15:27:15.994Z
Status : Awaiting Analysis
Published: 2026-09-30T21:16:55.743
Modified: 2026-10-01T16:17:33.157
Link: CVE-2026-102092
No data.
OpenCVE Enrichment
Updated: 2026-10-01T05:00:12Z