CVE-2026-30082

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Multiple stored cross-site scripting (XSS) vulnerabilities in the Edit feature of the Software Package List page of IngEstate Server v11.14.0 allow attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the About application, What's news, or Release note parameters.

Published 2026-03-30. Last modified 2026-07-05.