SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-38469

MEDIUM · CVSS 5.4 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A Stored XSS vulnerability exists in the custom bonus title feature of GazellePW, affecting the Java-based application. This flaw allows remote authenticated users to inject arbitrary JavaScript through the title parameter in specific PHP files, potentially compromising user sessions and data integrity. Organizations using GazellePW should prioritize patching this vulnerability to mitigate risks associated with unauthorized script execution.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-38469
Severity
MEDIUM
CVSS
5.4
EPSS
0.34%
Java

Original NVD Description

A Stored XSS vulnerability in the custom bonus title feature in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users to inject arbitrary JavaScript via the title parameter in /bonus.php and /user.php?action=staff_tool.