Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 22 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Deepl
Deepl chrome Browser Extension |
|
| Vendors & Products |
Deepl
Deepl chrome Browser Extension |
Wed, 22 Apr 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Site Scripting in DeepL Chrome Extension Enables Arbitrary Script Execution |
Wed, 22 Apr 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DeepL Chrome browser extension versions from v1.22.0 to v.1.23.0 contain a cross-site scripting vulnerability, which allows an attacker to execute arbitrary script in a user's browser, and inject malicious HTML into web pages viewed by the user. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2026-04-22T12:38:36.513Z
Reserved: 2026-04-13T06:27:03.647Z
Link: CVE-2026-40451
Updated: 2026-04-22T12:38:18.649Z
Status : Awaiting Analysis
Published: 2026-04-22T05:16:23.253
Modified: 2026-04-22T21:23:52.620
Link: CVE-2026-40451
No data.
OpenCVE Enrichment
Updated: 2026-04-22T11:44:48Z