CVE-2024-26018: Tvrock

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Cross-site scripting vulnerability exists in TvRock 0.9t8a. An arbitrary script may be executed on the web browser of the user accessing the website that uses the product. Note that the developer was unreachable, therefore, users should consider stop using TvRock 0.9t8a.

Affected products

  • Tvrock Tvrock: version 0.9t8a only

Published 2024-03-26. Last modified 2026-06-17.