SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-90569

LOW · CVSS 2.4

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

A cross-site scripting vulnerability exists in the Admin Topic Handler of linlinjava litemall versions 1.5.0 through 1.8.0, specifically within the AdminTopicController.validate function. This flaw allows remote attackers to execute arbitrary scripts in the context of the affected application, potentially compromising user data and session integrity. Organizations using these versions of litemall should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-90569
Severity
LOW
CVSS
2.4
EPSS
N/A
Java

Original NVD Description

A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopicController.validate of the file litemall-vue/src/views/items/topic/index.vue of the component Admin Topic Handler. This manipulation causes cross site scripting. The attack may be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.