CVE-2026-39275
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code via the item.php, field-select.js and tags.js components
Published 2026-08-26. Last modified 2026-08-31.