CVE-2026-40804 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kodezen LLC aBlocks ablocks allows Reflected …
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kodezen LLC aBlocks ablocks allows Reflected XSS.This issue affects aBlocks: from n/a through 2.16.0.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:LHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
Required
User Interaction
S
Changed
Scope
C
Low
Confidentiality
I
Low
Integrity
A
Low
Availability
Related threats
same CWE or vendorCVE-2026-84244 — IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulnerable to stored cross-site scripting (XSS) in the Quick Search resu…
CVE-2026-84244 · 2h ago
CVE-2026-107393 — FreeScout is a self-hosted help desk and shared mailbox.
CVE-2026-107393 · 2h ago
CVE-2026-107380 — savg-sanitizer is a PHP SVG/XML sanitizer.
CVE-2026-107380 · 4h ago
CVE-2026-107303 — JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures.
CVE-2026-107303 · 4h ago
CVE-2026-104078 — Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute …
CVE-2026-104078 · 5h ago
CVE-2026-104077 — Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting in…
CVE-2026-104077 · 5h ago