CVE-2026-36470
Medium severity, CVSS 5.8. EPSS: 0.2% chance of exploitation in the next 30 days.
CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the "Referer" header is copied into the response HTML unmodified/unescaped during POST messages to index.php.
Published 2026-09-21. Last modified 2026-09-22.