Impact
Improper neutralization of user input in Penci Filter Everything allows a DOM‑based cross‑site scripting flaw. The vulnerability can enable an attacker to inject and execute arbitrary client‑side scripts when a site visitor loads a page containing malicious input. This can lead to defacement, theft of user data, or redirection to malicious sites. The weakness is classified as CWE‑79.
Affected Systems
The affected product is PenciFilter Everything by PenciDesign. Any installation of the plugin with a version older than 1.7 is susceptible. This includes all releases from the earliest available version up to, but not including, 1.7.
Risk and Exploitability
The CVSS base score is 6.5, indicating a moderate severity. The EPSS score of less than 1% suggests a low exploitation probability at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is through a crafted URL or form input that the plugin processes client‑side; an attacker only needs a visitor’s browser to execute the injected script.
OpenCVE Enrichment
EUVD