Sceawere

Vulnerability Detail

CVE-2026-66467UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

FluentCommunity Cross Site Scripting Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
7h ago
Vendor
WPManageNinja
Product
FluentCommunity
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-13T14:17:08.097Z",
  "pubdate": "2026-08-13T14:17:08.097Z",
  "executiveSummary": "A security vulnerability categorized as Cross-Site Scripting (XSS) has been identified in FluentCommunity versions <= 2.7.5. This security flaw allows authenticated users with subscriber-level privileges to inject and execute arbitrary client-side scripts, such as JavaScript, within the context of other users' browser sessions when they interact with the vulnerable application interface. The vulnerability impacts the FluentCommunity platform and presents significant risk implications, potentially leading to unauthorized actions performed on behalf of victim users, session hijacking, credential theft, or the manipulation of the Document Object Model (DOM) within the affected web application. Exploitation of this vulnerability requires subscriber-level access to the target system, meaning the attacker must possess an authenticated low-privileged account to supply and store the malicious payload. No further complex exploitation requirements are specified beyond the capability to input malicious script data into the application fields or parameters processed by the vulnerable component. Security teams managing this software are advised to address the issue promptly to mitigate risks associated with untrusted input rendering and client-side code execution.",
  "technicalDetails": "The vulnerability resides in the FluentCommunity application within versions <= 2.7.5, specifically stemming from insufficient input sanitization and output encoding of user-supplied data before rendering it in the browser. Cross-Site Scripting (XSS) vulnerabilities of this nature typically occur when an application fails to properly neutralize special characters, such as angle brackets (< and >), quotes, and script tags, allowing injected markup to be interpreted and executed by the browser as active content. In this specific scenario, a threat actor leverages subscriber-level authentication privileges to submit a crafted payload containing malicious JavaScript through input vectors processed by the application. Because the application inadequately validates or sanitizes the input, the payload is persisted within the application database or reflected directly in the response without proper contextual output encoding. When a victim user accesses the affected page or component, the browser parses the malicious payload as part of the document structure. The attack flow begins with the authenticated subscriber authenticating to the platform and injecting the malicious script into a vulnerable parameter or field. Upon subsequent retrieval and rendering of this data by the application, the browser executes the injected script within the security context of the victim's session. The post-exploitation impact includes the potential theft of session cookies, bypass of CSRF tokens, execution of arbitrary actions via the victim's authenticated interface, and unauthorized data exfiltration. The vulnerability is accessible over network channels where the web application is exposed, requiring valid subscriber credentials for initial interaction but impacting any user type, including administrators, who subsequently view the rendered payload."
}
CVE-2026-66467: FluentCommunity Cross Site Scripting Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere