CVE-2026-50591: Znuny

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

In Znuny LTS before 6.5.21 and Znuny before 7.3.3, XSS can occur via stored user preferences.

Affected products

  • Znuny Znuny: from 6.0.0, before 6.5.21 (fixed in 6.5.21); from 7.0.0, before 7.3.3 (fixed in 7.3.3)

Published 2026-06-05. Last modified 2026-10-06.