SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-78178

HIGH · CVSS 7.3 EPSS 0.44% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A vulnerability in jQWidgets versions up to 24.0.1 allows remote attackers to manipulate object prototype attributes through the JQXLite.extend/jqxBaseFramework.extend functions in jqwidgets/jqx-all.js. This can lead to unauthorized modifications and potential exploitation of affected applications. Organizations using jQWidgets should prioritize patching or mitigating this vulnerability to safeguard against potential attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-78178
Severity
HIGH
CVSS
7.3
EPSS
0.44%
GitHub

Original NVD Description

A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/jqxBaseFramework.extend of the file jqwidgets/jqx-all.js. This manipulation causes improperly controlled modification of object prototype attributes. The attack can be initiated remotely. The reported GitHub issue was closed with the label "not planned".