Security Advisory

CVE-2026-22209

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-03-13 01:18:13
Last updated 2026-05-24 01:37:44
Assigner VulnCheck
State PUBLISHED

Description

wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability in the customCss field that allows administrators to inject malicious scripts by breaking out of style tags. Attackers with admin access can inject payloads like </style><script>alert(1)</script> in the custom CSS setting to execute arbitrary JavaScript in user browsers.