CVE-2026-36763: XSS
Published Apr 30, 2026
·Updated
A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted input into the content parameter.
Affected Software
1 affected component
SpringBlade SpringBlade=4.8.0
Event History
Apr 30, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-36763?
The severity of CVE-2026-36763 is medium with a score of 6.1.
2
What type of vulnerability is CVE-2026-36763?
CVE-2026-36763 is a stored cross-site scripting (XSS) vulnerability.
3
How do I fix CVE-2026-36763?
To fix CVE-2026-36763, sanitize and validate input on the /api/blade-desk/notice/submit endpoint to prevent arbitrary script execution.
4
What impact does CVE-2026-36763 have?
CVE-2026-36763 allows attackers to execute arbitrary web scripts or HTML, potentially compromising user data.
5
Which software is affected by CVE-2026-36763?
CVE-2026-36763 affects SpringBlade version 4.8.0.