Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 18 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Site Scripting in TOA TRIFORA 3 Network Camera Setup Screen |
Fri, 16 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Toa Corporation
Toa Corporation trifora 3 Series |
|
| Vendors & Products |
Toa Corporation
Toa Corporation trifora 3 Series |
|
| Metrics |
ssvc
|
Fri, 16 Jan 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-site scripting vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation. If an attacking administrator configures the affected product with some malicious input, an arbitrary script may be executed on the web browser of a victim administrator who accesses the setting screen. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2026-01-16T13:45:31.792Z
Reserved: 2026-01-14T04:14:33.376Z
Link: CVE-2026-20894
Updated: 2026-01-16T13:45:28.313Z
Status : Deferred
Published: 2026-01-16T09:16:22.650
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-20894
No data.
OpenCVE Enrichment
Updated: 2026-04-18T16:15:04Z