CVE-2026-35466: Stored XSS via unsanitized input from remote service
Published Apr 2, 2026
·Updated
XSS vulnerability in cveInterface.js allows for inject HTML to be passed to display, as cveInterface trusts input from CVE API services
Affected Software
1 affected component
cmu Cveclient<1.0.24
Remediation
Patch Available
Event History
Apr 2, 2026
CVE Published
via MITRE·08:20 PM
Data Sourced
via MITRE·08:20 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-35466?
The severity of CVE-2026-35466 is rated as medium with a score of 6.1.
2
What type of vulnerability is CVE-2026-35466?
CVE-2026-35466 is a stored cross-site scripting (XSS) vulnerability.
3
How do I fix CVE-2026-35466?
To fix CVE-2026-35466, apply the available patch provided by the software developer.
4
What software is affected by CVE-2026-35466?
CVE-2026-35466 affects the cmu Cveclient software.
5
What causes the vulnerability in CVE-2026-35466?
The vulnerability in CVE-2026-35466 is caused by unsanitized input from a remote service that allows HTML injection.