Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Jun 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cmu
Cmu cveclient |
|
| CPEs | cpe:2.3:a:cmu:cveclient:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cmu
Cmu cveclient |
Fri, 03 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cert/cc
Cert/cc cveclient/cveinterface.js |
|
| Vendors & Products |
Cert/cc
Cert/cc cveclient/cveinterface.js |
Thu, 02 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XSS vulnerability in cveInterface.js allows for inject HTML to be passed to display, as cveInterface trusts input from CVE API services | |
| Title | Stored XSS via unsanitized input from remote service | |
| Weaknesses | CWE-79 | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-04-03T13:55:40.446Z
Reserved: 2026-04-02T20:09:50.057Z
Link: CVE-2026-35466
Updated: 2026-04-03T13:53:25.522Z
Status : Analyzed
Published: 2026-04-02T21:16:40.687
Modified: 2026-06-17T10:40:38.817
Link: CVE-2026-35466
No data.
OpenCVE Enrichment
Updated: 2026-04-03T21:17:12Z