Impact
Vulnogram 1.0.0 holds a stored cross‑site scripting flaw in the way comment hypertext is processed. Attackers can inject malicious script code into comments, which is then executed by any browser that renders the comment.
Affected Systems
All installations of Vulnogram version 1.0.0, including the beta1 build, that expose public comment posting are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, while the EPSS of less than 1 % reflects a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can reach the flaw through the normal comment submission interface; the compromise occurs only within the victim’s browser and does not affect the server itself.
OpenCVE Enrichment
Github GHSA