Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present in the '/blog' endpoint because user input is not properly sanitized through designed query parameters. This results in unsafe HTML rendering, which could allow a remote attacker to execute JavaScript code in the victim's browser.

Project Subscriptions

Vendors Products
Navigate Subscribe
Navigate Cms Subscribe
Advisories

No advisories yet.

Fixes

Solution

The vulnerability has been fixed by Navigate CMS team in version 2.9.6.


Workaround

No workaround given by the vendor.

History

Tue, 21 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Apr 2026 09:45:00 +0000

Type Values Removed Values Added
Description Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present in the '/blog' endpoint because user input is not properly sanitized through designed query parameters. This results in unsafe HTML rendering, which could allow a remote attacker to execute JavaScript code in the victim's browser.
Title Reflected Cross-Site Scripting in Navigate CMS application
First Time appeared Navigate
Navigate navigate Cms
Weaknesses CWE-79
CPEs cpe:2.3:a:navigate:navigate_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:navigate:navigate_cms:2.9.6:*:*:*:*:*:*:*
Vendors & Products Navigate
Navigate navigate Cms
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-04-21T13:22:03.438Z

Reserved: 2026-02-27T10:16:01.748Z

Link: CVE-2026-3317

cve-icon Vulnrichment

Updated: 2026-04-21T13:21:44.751Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-21T10:16:30.623

Modified: 2026-04-21T16:20:24.180

Link: CVE-2026-3317

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses