CVE-2026-15928: Xmlrpc-C

High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.

XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.

Affected products

  • Xmlrpc-C Xmlrpc-C: from 1.07, up to and including 1.67.01; from 1.07, up to and including 1.64.03

Published 2026-07-27. Last modified 2026-07-27.