Description
Enterprise Cloud Database developed by Ragic has a Stored Cross-Site Scripting vulnerability, allowing unauthenticated remote attackers to inject persistent JavaScript code executed in users' browsers upon page load.
Published: 2026-07-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Ragic Enterprise Cloud Database is affected by a stored XSS flaw that permits unauthenticated remote attackers to inject persistent JavaScript code, which is executed in the browsers of users who access the affected page. This weakness is classified as CWE‑79 and enables the execution of arbitrary client‑side code. The impact is limited to the browser context of affected users and does not provide direct access to the database or server.

Affected Systems

Only the on‑premises installations of Ragic Enterprise Cloud Database that have not applied the patch released on or after April 10 2026 are affected. The hosted cloud version is not vulnerable and requires no action.

Risk and Exploitability

With a CVSS score of 5.3 this flaw carries a moderate risk. The EPSS score of less than 1 % indicates a low likelihood of exploitation, and it is not listed in the CISA KEV catalog, suggesting no known active exploits. Attackers who can supply malicious JavaScript that is stored by the application will have it executed in the browsers of users who load the affected pages.

Generated by OpenCVE AI on August 1, 2026 at 10:56 UTC.

Remediation

Vendor Solution

No action is required for the cloud version; the on-premises version must be updated to the patch released on or after April 10, 2026.


OpenCVE Recommended Actions

  • Apply the patch for on‑premises Ragic Enterprise Cloud Database released on or after 10 April 2026.
  • Validate and sanitize all user‑supplied data before storage, and encode or escape content rendered from the database to prevent embedded scripts.
  • Implement a strict Content Security Policy that disallows inline scripts and restricts allowed script sources to trusted domains.
  • Monitor application logs for abnormal or unexpected form submissions that could indicate attempts to inject malicious content.

Generated by OpenCVE AI on August 1, 2026 at 10:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Ragic
Ragic enterprise Cloud Database
Vendors & Products Ragic
Ragic enterprise Cloud Database

Mon, 13 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Description Enterprise Cloud Database developed by Ragic has a Stored Cross-Site Scripting vulnerability, allowing unauthenticated remote attackers to inject persistent JavaScript code executed in users' browsers upon page load.
Title Ragic|Enterprise Cloud Database - Stored Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Ragic Enterprise Cloud Database
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-07-14T14:33:35.498Z

Reserved: 2026-07-13T01:32:19.856Z

Link: CVE-2026-15552

cve-icon Vulnrichment

Updated: 2026-07-14T14:11:32.710Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:00:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')