CVE-2026-49259: NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
A stored cross-site scripting (XSS) vulnerability exists in NukeViet CMS versions 4.x through 4.5.08. A low-privileged authenticated user can store a JavaScript payload in their profile’s display name fields. The payload executes in the browser of any visitor — including administrators — who clicks the Reply (“Answer”) link on a comment posted by that user.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-49259 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →