What is CVE-2026-52475?
CVE-2026-52475 is a Cross Site Scripting (XSS) vulnerability found in 'aiflowy' versions 2.1.2 and earlier. The flaw allows a remote attacker to obtain sensitive information via the UploadController.java file. Users are strongly advised to update to the latest version immediately.
Azərbaycanca: CVE-2026-52475 'aiflowy' proqramının 2.1.2 və daha əvvəlki versiyalarında aşkar edilmiş Cross Site Scripting (XSS) zəifliyidir. Bu boşluq uzaqdan hücum edən şəxsə UploadController.java faylı vasitəsilə həssas məlumatları əldə etməyə imkan verir. İstifadəçilərə dərhal proqramı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What software does CVE-2026-52475 affect?
CVE-2026-52475 was discovered in 'aiflowy' versions 2.1.2 and earlier.
What can an attacker obtain by exploiting this vulnerability?
A remote attacker can obtain sensitive information via the UploadController.java file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.