ZeroHour

CVE-2026-88593

CVSS
EPSS
Published
()
Modified
Description

kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint. The OnlinePreviewController passes the user-controlled page and kkagent request parameters to FreeMarker templates without sanitization, and the templates insert these values into raw JavaScript contexts.

In the news

No ingested article mentions this CVE yet.