ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-23929
+3 in the same advisory: …1199 …23930 …23922
Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps.

Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that traversed the prototype chain.

NVD description · AI analysis pending
8.5
group max
<1%
  • zabbix zabbix