What is CVE-2026-18968?
A remote cross-site scripting (XSS) vulnerability exists in ttttonyhe OBlog in the /tags.php file due to improper handling of the 'day' argument. This issue affects versions up to commit 3ca6a45a2fcc81f6086751d8af124658720e8f8f. Users are advised to update to the latest version immediately.
Azərbaycanca: ttttonyhe OBlog sistemində /tags.php faylında 'day' parametrinin düzgün işlənməməsi səbəbindən uzaqdan cross-site scripting (XSS) hücumu mümkündür. Bu zəiflik 3ca6a45a2fcc81f6086751d8af124658720e8f8f commit-inə qədər olan versiyalara təsir edir. İstifadəçilərə dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of OBlog are affected by CVE-2026-18968?
This vulnerability affects versions of ttttonyhe OBlog up to commit 3ca6a45a2fcc81f6086751d8af124658720e8f8f.
How can I protect against the XSS vulnerability CVE-2026-18968?
Users are advised to update ttttonyhe OBlog to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.