Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 08 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:fogproject:fogproject:*:*:*:*:*:*:*:* |
Mon, 30 Mar 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fogproject
Fogproject fogproject |
|
| Vendors & Products |
Fogproject
Fogproject fogproject |
Sat, 28 Mar 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Mar 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.1812, the listing tables on multiple management pages (Host, Storage, Group, Image, Printer, Snapin) are vulnerable to Stored Cross-Site Scripting (XSS), due to insufficient server-side parameter sanitization in record creations/updates and a lack of HTML escaping in listing tables. Version 1.5.10.1812 patches the issue. | |
| Title | FOG has Stored XSS in Multiple Management Pages | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-27T20:29:44.713Z
Reserved: 2026-03-23T17:34:57.561Z
Link: CVE-2026-33739
Updated: 2026-03-27T20:29:41.292Z
Status : Analyzed
Published: 2026-03-27T20:16:33.423
Modified: 2026-04-08T15:08:44.030
Link: CVE-2026-33739
No data.
OpenCVE Enrichment
Updated: 2026-04-08T20:01:05Z