Sceawere
Vulnerability Detail
CVE-2026-94078UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated XSS in Site Reviews
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- Gemini Labs
- Product
- Site Reviews
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-09-30T13:17:23.350Z",
"pubdate": "2026-09-30T13:17:23.350Z",
"executiveSummary": "The vulnerability identified in Site Reviews versions 8.3.1 and below is an Unauthenticated Cross-Site Scripting (XSS) flaw. This security defect allows an unauthenticated remote attacker to inject malicious client-side scripts into web pages viewed by other users, including administrators.\nThe vulnerability arises from insufficient sanitization of user-supplied input before rendering it in the browser context. Because the flaw is exploitable without authentication, any visitor to the site can trigger the payload. The impact is significant, as successful exploitation enables session hijacking, unauthorized actions performed on behalf of legitimate users, credential theft, and the defacement of the affected website. This poses a critical risk to the integrity and confidentiality of the platform's user sessions and data.\nOrganizations relying on Site Reviews must treat this vulnerability with high priority, as it does not require prior knowledge of the target system or administrative access. The primary threat vector involves the delivery of a crafted payload to the vulnerable component, which is subsequently executed within the context of a victim's active session. Immediate patching or the implementation of strict input filtering is required to neutralize the threat.",
"technicalDetails": "The vulnerability is categorized as a Reflected or Stored Cross-Site Scripting (XSS) flaw, stemming from the improper handling of user-supplied data within the Site Reviews plugin ecosystem. In versions 8.3.1 and earlier, the application fails to adequately encode or sanitize input parameters before reflecting them back to the user's browser during page rendering or administrative dashboard interactions.\nThe root cause is identified as an input validation failure where the application trustfully processes data, such as review content, names, or custom fields, without enforcing strict output encoding mechanisms (e.g., HTML entity encoding). This allows an attacker to inject JavaScript, HTML tags, or other malicious content directly into the Document Object Model (DOM).\nThe attack flow proceeds as follows: An unauthenticated attacker crafts a malicious request containing a scripted payload. When this request is processed by the Site Reviews plugin, the payload is persisted or reflected by the server-side code. When an unsuspecting user, such as an administrator with high-privilege cookies, visits the affected page, the browser interprets the injected data as executable code rather than plain text. This execution occurs within the security context of the origin, granting the injected script access to the victim's session tokens (via document.cookie), LocalStorage, and the ability to perform actions on behalf of the victim via the Fetch or XMLHttpRequest APIs.\nSince the vulnerability is unauthenticated, the exploitation surface is the entire network. No specific administrative or low-privilege account is needed to initiate the injection. The payload behaves by hijacking the session or performing cross-site request forgery (CSRF) style attacks, effectively bypassing the security boundary intended to separate public-facing content from internal site administration. Once the script is executed, the post-exploitation impact includes the potential for full site takeover if the victim possesses administrative privileges, persistent malware redirection, or the exfiltration of sensitive platform configuration data displayed within the dashboard."
}