CVE-2026-19744: Maalfer Pentestify

Medium severity, CVSS 5.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute arbitrary JavaScript in the application origin via a Markdown link whose URL contains a double quote, which closes the anchor's href attribute because the renderer's sanitization step does not escape quotes

Affected products

  • Maalfer Pentestify: before 2.3.2 (fixed in 2.3.2)

Published 2026-08-13. Last modified 2026-09-01.