Description
SOY Gallery contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who is logging in to the product.
Published: 2026-08-28
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unvalidated Cross‑Site Scripting flaw in SOY Gallery that allows an attacker to inject and execute arbitrary JavaScript in the web browser of any user who logs into the product. This can lead to data theft, session hijacking, or malicious content injection from the victim’s perspective.

Affected Systems

The flaw affects the SOY Gallery application developed by Tsuyoshi Saito. No specific affected versions are listed in the advisory, so all releases of the product remain potentially vulnerable until a patch is applied.

Risk and Exploitability

The issue carries a CVSS score of 4.8, indicating a moderate impact. EPSS data is not available, and the vulnerability is not currently listed in CISA’s KEV catalog. The likely attack vector is remote via the web, with the attacker needing to lure a logged‑in user into the vulnerable portion of the application.

Generated by OpenCVE AI on August 28, 2026 at 08:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched release of SOY Gallery once it becomes available.
  • If a patch is not yet available, add security headers such as Content‑Security‑Policy and X‑XSS‑Protection to the web server to mitigate XSS risks.
  • Deploy a web‑application firewall or similar filtering to detect and block malicious scripts before they reach the browser.

Generated by OpenCVE AI on August 28, 2026 at 08:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting Vulnerability in SOY Gallery Enables Arbitrary Script Execution

Fri, 28 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Description SOY Gallery contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who is logging in to the product.
Weaknesses CWE-79
References
Metrics cvssV3_0

{'score': 5.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-28T06:11:06.057Z

Reserved: 2026-08-24T04:26:32.279Z

Link: CVE-2026-78238

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T08:16:42.030

Modified: 2026-08-28T08:16:42.030

Link: CVE-2026-78238

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T09:00:10Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')