What is CVE-2026-48539?
GFI Archiver versions before 15.13 contain a stored XSS vulnerability in the MailInsights scheduled report configuration. This allows authenticated attackers to inject arbitrary web script or HTML via the 'report name' parameter, which is then stored. Users should immediately upgrade to version 15.13 or later.
Azərbaycanca: GFI Archiver-in 15.13-dən əvvəlki versiyalarında, MailInsights hesabat konfiqurasiyasında saxlanılan XSS zəifliyi aşkar edilib. Bu, autentifikasiya olunmuş hücumçulara 'report name' parametri vasitəsilə zərərli skript yükləməyə imkan verir. İstifadəçilər dərhal 15.13 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: GFI
FAQ2
Which versions of GFI Archiver are affected by CVE-2026-48539?
This stored XSS vulnerability affects GFI Archiver versions before 15.13.
How can users protect against CVE-2026-48539?
Users should immediately upgrade GFI Archiver to version 15.13 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.