NONE · 0

CVE-2026-19744

Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute arbitrary JavaScript in the application origin via a Markdown link whose URL cont...

Vulnerability Description

Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute arbitrary JavaScript in the application origin via a Markdown link whose URL contains a double quote, which closes the anchor's href attribute because the renderer's sanitization step does not escape quotes

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-19744?

CVE-2026-19744 is a documented vulnerability. Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute arbitrary JavaScript in the application origin via a Markdown link whose URL cont...

How severe is CVE-2026-19744?

CVSS scoring is not yet available for CVE-2026-19744. Check NVD for updates.

Is there a patch for CVE-2026-19744?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.