CVE-2026-19434: Maalfer Pentestify
Medium severity, CVSS 5.1. EPSS: 0.5% chance of exploitation in the next 30 days.
Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the application origin via HTML markup stored in a finding's severity field, which the frontend interpolates unescaped into class and style attributes when rendering the report.
Affected products
- Maalfer Pentestify: before 2.3.1 (fixed in 2.3.1)
Published 2026-08-11. Last modified 2026-09-01.