SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-38465

MEDIUM · CVSS 5.4 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability affects the GazellePW (GazellePosterWall) feature, specifically allowing remote authenticated users to inject arbitrary JavaScript through the avatar mouse-over text parameter. This stored XSS flaw could lead to unauthorized script execution in the context of other users, potentially compromising sensitive data or user sessions. Organizations utilizing GazellePW should prioritize remediation to protect against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-38465
Severity
MEDIUM
CVSS
5.4
EPSS
0.34%
Java

Original NVD Description

A Stored XSS vulnerability in the donor avatar mouse-over text feature in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users to inject arbitrary JavaScript via the avatar_mouse_over_text parameter, which is stored and later rendered in avatar tooltip.