What is CVE-2026-52606?
CVE-2026-52606 is a reflected cross-site scripting (XSS) vulnerability in reportico-web version 8.1.0 and below. A remote attacker can execute arbitrary JavaScript in a user's browser by injecting a malicious payload into the loadTemplate parameter alongside execute_mode=PREPARE in run.php. Updating the application or strengthening input filtering is recommended.
Azərbaycanca: CVE-2026-52606, reportico-web <= 8.1.0 tətbiqində aşkarlanmış reflected cross-site scripting (XSS) zəifliyidir. Uzaqdan hücumçu run.php səhifəsində loadTemplate parametrinə execute_mode=PREPARE ilə zərərli skript yerləşdirərək istifadəçinin brauzerində JavaScript icrasına nail ola bilər. Tətbiqi son versiyaya yeniləmək və ya giriş filtrasiyasını gücləndirmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of reportico-web are affected by CVE-2026-52606?
CVE-2026-52606 affects reportico-web version 8.1.0 and below.
Which parameters in run.php does an attacker manipulate to exploit the XSS vulnerability in CVE-2026-52606?
An attacker exploits the XSS vulnerability by injecting a malicious script into the loadTemplate parameter alongside execute_mode=PREPARE in run.php.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.