Impact
The Ragic Enterprise Cloud Database is affected by a stored XSS flaw that permits unauthenticated remote attackers to inject persistent JavaScript code, which is executed in the browsers of users who access the affected page. This weakness is classified as CWE‑79 and enables the execution of arbitrary client‑side code. The impact is limited to the browser context of affected users and does not provide direct access to the database or server.
Affected Systems
Only the on‑premises installations of Ragic Enterprise Cloud Database that have not applied the patch released on or after April 10 2026 are affected. The hosted cloud version is not vulnerable and requires no action.
Risk and Exploitability
With a CVSS score of 5.3 this flaw carries a moderate risk. The EPSS score of less than 1 % indicates a low likelihood of exploitation, and it is not listed in the CISA KEV catalog, suggesting no known active exploits. Attackers who can supply malicious JavaScript that is stored by the application will have it executed in the browsers of users who load the affected pages.
OpenCVE Enrichment