What is CVE-2026-19988?
A Basic Cross-Site Scripting (XSS) vulnerability exists in Alaev SEO Tools Extension up to version 1.0.10, specifically in the Popup UI component's 'addDiv' function. This allows a remote attacker to execute scripts in the victim's browser context. Users are advised to urgently apply the security update from the vendor or temporarily disable the extension.
Azərbaycanca: Alaev SEO Tools genişlənməsinin 1.0.10-a qədər versiyalarında Popup UI komponentində Basic Cross-Site Scripting (XSS) zəifliyi aşkarlanıb. Uzaqdan hücum edən tərəf 'addDiv' funksiyası vasitəsilə qurbanın kontekstində skript icra edə bilər. İstifadəçilərə genişlənməni müvəqqəti deaktiv etməklə yanaşı, tərtibatçının təhlükəsizlik yeniləməsini təcili tətbiq etməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
In which component of the Alaev SEO Tools Extension is the CVE-2026-19988 vulnerability located, and how can it be exploited?
The vulnerability is located in the 'addDiv' function of the extension's Popup UI component. This Basic Cross-Site Scripting (XSS) flaw allows a remote attacker to execute scripts in the victim's browser context.
What urgent steps are recommended for users to protect against CVE-2026-19988?
Users are advised to urgently apply the security update provided by the vendor. If the update is not yet available, temporarily disabling the extension is recommended as a mitigation measure.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.