---
id: CVE-2026-4765
title: >-
  Self Cross-Site Scripting (Self-XSS) vulnerability in the RD Station Conversas
  chat feature
summary: >-
  Self Cross-Site Scripting (Self-XSS) vulnerability in the RD Station Conversas
  chat feature. The vulnerability lies in the ‘name’ parameter of the
  initialisation process due to incorrect sanitisation of user-supplied input.
  Exploitation …
severity: none
cvss: 0
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-79
vendor: RD Station Conversas
product: Tallos Chat
affected:
  - tallos_chat all versions
published: '2026-07-13'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T12:17:12.220'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-4765'
references:
  - url: >-
      https://www.incibe.es/en/incibe-cert/notices/aviso/stored-cross-site-scripting-xss-tallos-chat-rd-station-conversas
    label: cve-coordination@incibe.es
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-13T13:14:09.748715Z'
cvssSource: cna
epss: 0.00436
epssPercentile: 0.37424
ingestedAt: '2026-09-09T12:08:31.841Z'
---

## Overview

Self Cross-Site Scripting (Self-XSS) vulnerability in the RD Station Conversas chat feature. The vulnerability lies in the ‘name’ parameter of the initialisation process due to incorrect sanitisation of user-supplied input. Exploitation allows specially crafted JavaScript code to be injected, which is executed within the context of the user’s own session who provides the payload. The demonstrated impact is limited to the user who enters and executes the payload.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
