CVE-2016-1000028: Tenable Nessus

Medium severity, CVSS 4.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would only potentially impact other admins. (Tenable ID 5198).

Affected products

  • Tenable Nessus: before 6.8.0 (fixed in 6.8.0)

Published 2019-12-27. Last modified 2026-06-17.