CVE-2026-19434: Maalfer Pentestify

Medium severity, CVSS 5.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the application origin via HTML markup stored in a finding's severity field, which the frontend interpolates unescaped into class and style attributes when rendering the report.

Affected products

  • Maalfer Pentestify: before 2.3.1 (fixed in 2.3.1)

Published 2026-08-11. Last modified 2026-09-01.