CVE-2026-88593
—CVSS
—
EPSS
—
Published
()
Modified
Description
kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint. The OnlinePreviewController passes the user-controlled page and kkagent request parameters to FreeMarker templates without sanitization, and the templates insert these values into raw JavaScript contexts.
In the news0 stories
No ingested article mentions this CVE yet.