CVE-2026-1434

Publication date

2026-02-27 10:32:53

Family

CERT-PL

State

PUBLISHED

Description

Omega-PSIR is vulnerable to Reflected XSS via the lang parameter. An attacker can craft a malicious URL that, when opened, causes arbitrary JavaScript to execute in the victim’s browser. This issue was fixed in 4.6.7.