Description
Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present in the '/blog' endpoint because user input is not properly sanitized through designed query parameters. This results in unsafe HTML rendering, which could allow a remote attacker to execute JavaScript code in the victim's browser.
Published: 2026-04-21
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

The vulnerability has been fixed by Navigate CMS team in version 2.9.6.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Apr 2026 09:45:00 +0000

Type Values Removed Values Added
Description Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present in the '/blog' endpoint because user input is not properly sanitized through designed query parameters. This results in unsafe HTML rendering, which could allow a remote attacker to execute JavaScript code in the victim's browser.
Title Reflected Cross-Site Scripting in Navigate CMS application
First Time appeared Navigate
Navigate navigate Cms
Weaknesses CWE-79
CPEs cpe:2.3:a:navigate:navigate_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:navigate:navigate_cms:2.9.6:*:*:*:*:*:*:*
Vendors & Products Navigate
Navigate navigate Cms
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Navigate Navigate Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-04-21T13:22:03.438Z

Reserved: 2026-02-27T10:16:01.748Z

Link: CVE-2026-3317

cve-icon Vulnrichment

Updated: 2026-04-21T13:21:44.751Z

cve-icon NVD

Status : Received

Published: 2026-04-21T10:16:30.623

Modified: 2026-04-21T10:16:30.623

Link: CVE-2026-3317

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses