SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-78213

HIGH · CVSS 8.7 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Heptabase, developed by Hepta Platforms, Inc., is vulnerable to a Stored Cross-Site Scripting (XSS) flaw that allows authenticated remote attackers to inject persistent malicious scripts into specific pages. This vulnerability can lead to the execution of arbitrary JavaScript code when unsuspecting users interact with the compromised content, potentially compromising user data and session integrity. Organizations using Heptabase should prioritize remediation efforts to mitigate the risk of exploitation and protect their users.

CVE
CVE-2026-78213
Severity
HIGH
CVSS
8.7
EPSS
0.31%
Java

Original NVD Description

Heptabase developed by Hepta Platforms, Inc. has a Stored Cross-Site Scripting vulnerability. Authenticated remote attackers can inject persistent malicious content into specific pages, causing arbitrary JavaScript code to execute when other users click the crafted content.