CVE-2026-78178

High severity, CVSS 7.3. EPSS: 0.6% chance of exploitation in the next 30 days.

A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/jqxBaseFramework.extend of the file jqwidgets/jqx-all.js. This manipulation causes improperly controlled modification of object prototype attributes. The attack can be initiated remotely. The reported GitHub issue was closed with the label "not planned".

Published 2026-08-24. Last modified 2026-08-27.