What is CVE-2026-28082?
CVE-2026-28082 is an unauthenticated Cross Site Scripting (XSS) vulnerability affecting JetEngine versions up to 3.8.13.1. It allows attackers to inject malicious scripts without user interaction. Immediate update to the latest version is recommended.
Azərbaycanca: CVE-2026-28082, JetEngine-in 3.8.13.1 və daha əvvəl versiyalarını təsir edən təsdiqlənməmiş (unauthenticated) Cross Site Scripting (XSS) zəifliyidir. Bu, təcavüzkara istifadəçi girişi olmadan zərərli skript yeritməyə imkan verir. Dərhal JetEngine plaginini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which plugin is affected by CVE-2026-28082 and who can exploit this vulnerability?
CVE-2026-28082 affects the JetEngine plugin. As it is an unauthenticated XSS vulnerability, attackers can inject malicious scripts without any user interaction, meaning anyone could potentially exploit it.
What should I do to protect against CVE-2026-28082?
You should immediately update the JetEngine plugin to the latest version. Since this vulnerability affects versions up to 3.8.13.1, updating will resolve the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.