CVE-2023-28367: Vektor-Inc Vk All In One Expansion Unit

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

Cross-site scripting vulnerability in CTA post function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary script.

Affected products

  • Vektor-Inc Vk All In One Expansion Unit: before 9.88.2.0 (fixed in 9.88.2.0)

Published 2023-05-23. Last modified 2026-06-17.