Sceawere

Vulnerability Detail

CVE-2026-94667UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in JetReviews

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Crocoblock
Product
JetReviews
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetReviews jet-reviews allows Stored XSS.This issue affects JetReviews: from n/a through 3.1.2.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-09T10:16:41.823Z",
  "pubdate": "2026-10-09T10:16:41.823Z",
  "executiveSummary": "The Crocoblock JetReviews plugin is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This security flaw is categorized as an Improper Neutralization of Input During Web Page Generation issue, allowing attackers to inject and persist malicious scripts within the application's database.\nThe vulnerability affects JetReviews versions ranging from n/a through 3.1.2. By exploiting this flaw, an attacker can store arbitrary JavaScript payloads that execute within the browser context of other users, including administrators, when they access affected pages or review management interfaces.\nThe primary risk implication involves the compromise of user sessions, unauthorized execution of actions on behalf of authenticated users, and the potential for defacement or redirection. Successful exploitation typically requires an attacker to possess the capability to submit input that is subsequently stored and rendered without adequate sanitization. This vulnerability highlights a failure in input validation and output encoding mechanisms, exposing the integrity and confidentiality of the web application and its end-users to remote exploitation.",
  "technicalDetails": "The vulnerability originates from a failure in the JetReviews plugin to properly sanitize user-supplied input before persisting it into the database and rendering it back in the administrative or public-facing views. Stored XSS, or persistent XSS, occurs when an application receives data from an untrusted source and includes that data within its later HTTP responses in an unsafe manner.\nIn the context of JetReviews, the attack flow begins with the injection of a malicious payload, typically a JavaScript snippet, into an input field processed by the plugin. If the application lacks robust server-side input validation, the malicious script is stored in the database. When a victim, such as an administrator or another user, views the specific page, review section, or dashboard where this malicious content is rendered, the browser interprets the script as legitimate code originating from the trusted domain.\nThe execution happens because the plugin fails to implement sufficient output encoding. When the browser receives the HTML response containing the unsanitized payload, it executes the embedded JavaScript. Because this script executes within the context of the vulnerable site's origin, it can access cookies, session tokens, and sensitive data stored in the LocalStorage or SessionStorage of the user's browser.\nThe scope of impact is significant; an attacker can hijack the session of a logged-in administrator, potentially leading to a full site takeover, or perform actions such as modifying configurations, creating rogue administrative accounts, or injecting further malicious content into the site. The vulnerability does not necessarily require advanced exploitation techniques; rather, it relies on the application's failure to adhere to secure coding practices regarding Data Sanitization and Context-Aware Output Encoding. The lack of validation on fields processed by JetReviews allows for this persistent vector, ensuring that every user who interacts with the affected content becomes a potential target for the injected script."
}
CVE-2026-94667: Stored XSS in JetReviews (MEDIUM Severity, CVSS: 6.5) | Sceawere