Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vertigis fm
|
|
| CPEs | cpe:2.3:a:vertigis:fm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vertigis fm
|
|
| Metrics |
cvssV3_1
|
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A reflected cross-site scripting (XSS) vulnerability in the dashboard search functionality of the VertiGIS FM solution allows attackers to craft a malicious URL, that if visited by an authenticated victim, will execute arbitrary JavaScript in the victim's context. Such a URL could be delivered through various means, for instance, by sending a link or by tricking victims to visit a page crafted by the attacker. | |
| Title | Reflected Cross-Site Scripting in Dashboard Search | |
| First Time appeared |
Vertigis
Vertigis vertigis Fm |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:vertigis:vertigis_fm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vertigis
Vertigis vertigis Fm |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2026-04-01T13:33:40.924Z
Reserved: 2026-03-10T12:01:10.709Z
Link: CVE-2026-3877
Updated: 2026-04-01T13:33:23.711Z
Status : Analyzed
Published: 2026-04-01T14:16:58.130
Modified: 2026-04-02T19:36:47.993
Link: CVE-2026-3877
No data.
OpenCVE Enrichment
Updated: 2026-04-03T09:19:07Z