Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 20 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 20 Jan 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HTML injection vulnerability in multiple Botble products such as TransP, Athena, Martfury, and Homzen, consisting of an HTML injection due to a lack of proper validation of user input by sending a request to '/search' using the 'q' parameter. | |
| Title | HTML injection in multiple Botble products | |
| First Time appeared |
Botble
Botble athena Botble homzen Botble martfury Botble transp |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:botble:athena:all_versions:*:*:*:*:*:*:* cpe:2.3:a:botble:homzen:all_versions:*:*:*:*:*:*:* cpe:2.3:a:botble:martfury:all_versions:*:*:*:*:*:*:* cpe:2.3:a:botble:transp:all_versions:*:*:*:*:*:*:* |
|
| Vendors & Products |
Botble
Botble athena Botble homzen Botble martfury Botble transp |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-01-20T17:51:26.528Z
Reserved: 2026-01-19T12:17:38.221Z
Link: CVE-2026-1183
Updated: 2026-01-20T17:46:45.361Z
Status : Deferred
Published: 2026-01-20T13:16:03.180
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-1183
No data.
OpenCVE Enrichment
Updated: 2026-04-18T05:00:06Z