SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-2342

CRITICAL · CVSS 9.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

The vulnerability in ValeApp allows for stored cross-site scripting (XSS), enabling attackers to inject malicious scripts that can execute in the context of users' browsers. This critical flaw poses a significant risk, as it can lead to data theft, session hijacking, and unauthorized actions on behalf of users. Organizations using ValeApp should prioritize immediate remediation efforts to mitigate potential exploitation.

CVE
CVE-2026-2342
Severity
CRITICAL
CVSS
9.3
EPSS
0.22%

Original NVD Description

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS. This issue affects ValeApp: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.