NUWCDIVNPT Vulnerabilities and Affected Products
Vulnerabilities associated with stig-manager.
Products
Clear product- stig-manager1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-41200HIGH | STIG Manager has reflected XSS vulnerability in the Web AppSTIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) assessments of Information Systems. Versions 1.5.10 through 1.6.7 have a reflected Cross-Site Scripting (XSS) vulnerability in the OIDC authentication error handling code in `src/init.js` and `public/reauth.html`. During the OIDC redirect flow, the `error` and `error_description` query parameters returned by the OIDC provider are written directly to the DOM via `innerHTML` without HTML escaping. A… CWE-79Apr 23, 2026 | CVSS8.5v4.0 | EPSS0.332% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |