CVE-2026-36748
Critical severity, CVSS 9.0. EPSS: 0.4% chance of exploitation in the next 30 days.
RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.
Published 2026-06-03. Last modified 2026-07-22.