Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 24 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 23 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Crawl4ai
Crawl4ai crawl4ai |
|
| Vendors & Products |
Crawl4ai
Crawl4ai crawl4ai |
Tue, 23 Jun 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Crawl4AI before 0.8.7 contains a stored cross-site scripting vulnerability in the monitor dashboard that renders crawl URLs and error messages via innerHTML without escaping. An attacker can submit a crafted crawl request with malicious markup that executes in an operator's browser when viewing the dashboard. | |
| Title | Crawl4AI - Stored Cross-Site Scripting in Monitor Dashboard | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-24T15:11:55.336Z
Reserved: 2026-06-20T01:42:20.615Z
Link: CVE-2026-56263
Updated: 2026-06-24T15:11:42.440Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-23T21:03:03Z