---
id: CVE-2026-27787
title: Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier
summary: >-
  Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier. If
  this vulnerability is exploited, an arbitrary script may be executed on the
  web browser of the user who accessed the website using the product.
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: icz
product: matcha_sns
affected:
  - matcha_sns <= 1.3.9
published: '2026-04-08'
updated: '2026-07-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-27787'
references:
  - url: 'https://jvn.jp/en/jp/JVN33581068/'
    label: vultures@jpcert.or.jp
  - url: 'https://oss.icz.co.jp/news/?p=1388'
    label: vultures@jpcert.or.jp
tags:
  - nvd
epss: 0.00244
epssPercentile: 0.13849
ingestedAt: '2026-07-25T23:05:58.776Z'
---

## Overview

Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.

## Affected

- `matcha_sns <= 1.3.9`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
