CVE-2026-53737: Saas.group Juicer
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the connected feed data can inject script that executes in an administrator's browser when the settings page loads.
Affected products
- Saas.group Juicer: up to and including 1.12.18
Published 2026-06-10. Last modified 2026-07-23.