PasswordPusher Vulnerabilities and Affected Products
Vulnerabilities associated with PasswordPusher.
Products
Clear product- PasswordPusher1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-59802MEDIUM | PasswordPusher < 2.8.1 - Redirect-Based XSS via data URI in URL Push PayloadPasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can create malicious pushes containing data:text/html URIs that execute arbitrary JavaScript in victims' browsers when clicked, enabling phishing and credential theft under the trusted PasswordPusher domain. CWE-183Jul 8, 2026 | CVSS6.3v4.0 | EPSS0.192% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |