CVE-2024-34058: Nethesis Nethserver

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

The WebTop package for NethServer 7 and 8 allows stored XSS (for example, via the Subject field if an e-mail message).

Affected products

  • Nethesis Nethserver: version 7 only; version 8 only

Published 2024-05-17. Last modified 2026-06-17.