CVE-2026-19852: Cybertutor Newsiteserver Nss
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload arbitrary files, including malicious HTML files, thereby achieving effects similar to cross-site scripting.
Affected products
- Cybertutor Newsiteserver Nss: any version
Published 2026-08-24. Last modified 2026-08-26.