CVE-2026-36748

Critical severity, CVSS 9.0. EPSS: 0.4% chance of exploitation in the next 30 days.

RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.

Published 2026-06-03. Last modified 2026-07-22.