Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 03 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:leepeuker:movary:*:*:*:*:*:*:*:* |
Tue, 20 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 20 Jan 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Leepeuker
Leepeuker movary |
|
| Vendors & Products |
Leepeuker
Leepeuker movary |
Mon, 19 Jan 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-site scripting payloads in versions prior to 0.70.0. The vulnerable parameter is `?categoryDeleted=`. Version 0.70.0 fixes the issue. | |
| Title | Movary vulnerable to Cross-site Scripting with `?categoryDeleted=` param | |
| Weaknesses | CWE-20 CWE-79 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-20T17:30:24.315Z
Reserved: 2026-01-16T15:46:40.842Z
Link: CVE-2026-23840
Updated: 2026-01-20T17:30:15.565Z
Status : Analyzed
Published: 2026-01-19T19:16:04.227
Modified: 2026-02-03T14:47:15.050
Link: CVE-2026-23840
No data.
OpenCVE Enrichment
Updated: 2026-04-18T16:00:04Z