Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 02 Feb 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:leepeuker:movary:*:*:*:*:*:*:*:* |
Tue, 20 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 20 Jan 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Leepeuker
Leepeuker movary |
|
| Vendors & Products |
Leepeuker
Leepeuker movary |
Mon, 19 Jan 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-site scripting payloads in versions prior to 0.70.0. The vulnerable parameter is `?categoryCreated=`. Version 0.70.0 fixes the issue. | |
| Title | Movary vulnerable to Cross-site Scripting with `?categoryCreated=` param | |
| Weaknesses | CWE-20 CWE-79 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-20T20:05:55.115Z
Reserved: 2026-01-16T15:46:40.842Z
Link: CVE-2026-23841
Updated: 2026-01-20T20:02:45.928Z
Status : Analyzed
Published: 2026-01-19T19:16:04.370
Modified: 2026-02-02T15:17:06.853
Link: CVE-2026-23841
No data.
OpenCVE Enrichment
Updated: 2026-04-18T05:15:15Z