{"id":"CVE-2026-32774","title":"Vulnogram 1.0.0 contains a stored cross-site scripting vulnerability in comment hypertext handling that allows attackers to inject malicious scripts","summary":"Vulnogram 1.0.0 contains a stored cross-site scripting vulnerability in comment hypertext handling that allows attackers to inject malicious scripts. Remote attackers can inject XSS payloads through comments to execute arbitrary JavaScri…","severity":"medium","cvss":6.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"vulnogram","product":"vulnogram","affected":["vulnogram = 1.0.0"],"published":"2026-03-16","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:17:13.017","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-32774","references":[{"url":"https://github.com/Vulnogram/Vulnogram","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Vulnogram/Vulnogram/security/advisories/GHSA-pg4p-2985-gvxr","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/vulnogram-stored-cross-site-scripting-via-comment-hypertext","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Vulnogram/Vulnogram/commit/2f0e21b113c58124084c7b74c9768fc241126a05","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-03-16T14:16:20.173901Z"},"epss":0.00368,"epssPercentile":0.28613,"ingestedAt":"2026-10-08T16:52:14.675Z","slug":"CVE-2026-32774","body":"## Overview\n\nVulnogram 1.0.0 contains a stored cross-site scripting vulnerability in comment hypertext handling that allows attackers to inject malicious scripts. Remote attackers can inject XSS payloads through comments to execute arbitrary JavaScript in victims' browsers.\n\n## Affected\n\n- `vulnogram = 1.0.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":35.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}