CVE-2026-19434: Stored Cross-site Scripting in Pentestify finding severity field
Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the application origin via HTML markup stored in a finding's severity field, which the frontend interpolates unescaped into class and style attributes when rendering the report.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maalfer Pentestifyto a version that resolves this vulnerability.Fixed in 2.3.1