Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vggc-6pg2-xvp9 | Vulnogram contains a stored cross-site scripting vulnerability in comment hypertext handling |
Fri, 20 Mar 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:vulnogram:vulnogram:1.0.0:beta1:*:*:*:*:*:* |
Thu, 19 Mar 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 17 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:vulnogram:vulnogram:1.0.0:*:*:*:*:*:*:* | |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Mon, 16 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vulnogram
Vulnogram vulnogram |
|
| Vendors & Products |
Vulnogram
Vulnogram vulnogram |
Sat, 14 Mar 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnogram 1.0.0 contains a stored cross-site scripting vulnerability in comment hypertext handling that allows attackers to inject malicious scripts. Remote attackers can inject XSS payloads through comments to execute arbitrary JavaScript in victims' browsers. | |
| Title | Vulnogram - Stored Cross-Site Scripting via Comment Hypertext | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-19T17:49:50.974Z
Reserved: 2026-03-14T21:26:03.800Z
Link: CVE-2026-32774
Updated: 2026-03-19T17:49:50.974Z
Status : Analyzed
Published: 2026-03-16T14:19:44.207
Modified: 2026-03-20T18:26:35.590
Link: CVE-2026-32774
No data.
OpenCVE Enrichment
Updated: 2026-03-23T13:39:05Z
Github GHSA