{"id":"CVE-2026-12683","title":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc","summary":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS.\n\nThis issue affects LIBRID/LIBREF: from 2.01.0.2183 before 18.9…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"Ankaref Innovation and Technology Inc.","product":"LIBRID/LIBREF","affected":["LIBRID/LIBREF >= 2.01.0.2183 < 18.9.26.2319"],"published":"2026-09-10","updated":"2026-09-23","sourceUpdated":"2026-09-23T09:17:07.490","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-12683","references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1064","label":"iletisim@usom.gov.tr"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-10T17:07:28.884072Z"},"epss":0.00162,"epssPercentile":0.05793,"ingestedAt":"2026-09-14T11:54:35.028Z","slug":"CVE-2026-12683","body":"## Overview\n\nImproper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS.\n\nThis issue affects LIBRID/LIBREF: from 2.01.0.2183 before 18.9.26.2319.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}