No analysis available yet.
Vendor Solution
The vulnerability has been fixed by Navigate CMS team in version 2.9.6.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 21 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 21 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present in the '/blog' endpoint because user input is not properly sanitized through designed query parameters. This results in unsafe HTML rendering, which could allow a remote attacker to execute JavaScript code in the victim's browser. | |
| Title | Reflected Cross-Site Scripting in Navigate CMS application | |
| First Time appeared |
Navigate
Navigate navigate Cms |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:navigate:navigate_cms:*:*:*:*:*:*:*:* cpe:2.3:a:navigate:navigate_cms:2.9.6:*:*:*:*:*:*:* |
|
| Vendors & Products |
Navigate
Navigate navigate Cms |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-04-21T13:22:03.438Z
Reserved: 2026-02-27T10:16:01.748Z
Link: CVE-2026-3317
Updated: 2026-04-21T13:21:44.751Z
Status : Received
Published: 2026-04-21T10:16:30.623
Modified: 2026-04-21T10:16:30.623
Link: CVE-2026-3317
No data.
OpenCVE Enrichment
No data.