CVE-2024-41349: Unmark

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

unmark 1.9.2 is vulnerable to Cross Site Scripting (XSS) via application/views/marks/add_by_url.php.

Affected products

  • Unmark Unmark: version 1.9.2 only

Published 2024-08-29. Last modified 2026-06-17.