CVE-2026-4494: Atjiu Pybbs

Low severity, CVSS 3.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability was identified in atjiu pybbs 6.0.0. This affects the function create of the file src/main/java/co/yiiu/pybbs/controller/api/TopicApiController.java. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

Affected products

  • Atjiu Pybbs: version 6.0.0 only

Published 2026-03-20. Last modified 2026-06-17.