---
id: CVE-2026-32774
title: >-
  Vulnogram 1.0.0 contains a stored cross-site scripting vulnerability in
  comment hypertext handling that allows attackers to inject malicious scripts
summary: >-
  Vulnogram 1.0.0 contains a stored cross-site scripting vulnerability in
  comment hypertext handling that allows attackers to inject malicious scripts.
  Remote attackers can inject XSS payloads through comments to execute arbitrary
  JavaScri…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: vulnogram
product: vulnogram
affected:
  - vulnogram = 1.0.0
published: '2026-03-16'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:13.017'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-32774'
references:
  - url: 'https://github.com/Vulnogram/Vulnogram'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Vulnogram/Vulnogram/security/advisories/GHSA-pg4p-2985-gvxr
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/vulnogram-stored-cross-site-scripting-via-comment-hypertext
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Vulnogram/Vulnogram/commit/2f0e21b113c58124084c7b74c9768fc241126a05
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-03-16T14:16:20.173901Z'
epss: 0.00368
epssPercentile: 0.28613
ingestedAt: '2026-10-08T16:52:14.675Z'
---

## Overview

Vulnogram 1.0.0 contains a stored cross-site scripting vulnerability in comment hypertext handling that allows attackers to inject malicious scripts. Remote attackers can inject XSS payloads through comments to execute arbitrary JavaScript in victims' browsers.

## Affected

- `vulnogram = 1.0.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
