CVE-2026-1959: Loggro Pymes

Medium severity, CVSS 5.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes, via the 'descripción' parameter in the '/loggrodemo/jbrain/MaestraCuentasBancarias' endpoint.

Affected products

  • Loggro Pymes Loggro Pymes: before 1.0.124 (fixed in 1.0.124)

Published 2026-02-09. Last modified 2026-06-17.