CVE-2026-1434

MEDIUM

Omega-PSIR <4.6.7 - XSS

Title source: llm

Description

Omega-PSIR is vulnerable to Reflected XSS via the lang parameter. An attacker can craft a malicious URL that, when opened, causes arbitrary JavaScript to execute in the victim’s browser. This issue was fixed in 4.6.7.

Exploits (1)

nomisec WRITEUP
by lukasz-rybak · poc
https://github.com/lukasz-rybak/CVE-2026-1434

Scores

CVSS v3 6.1
EPSS 0.0003
EPSS Percentile 10.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
pw/omega-psir 4.5.9 - 4.6.7
Published Feb 27, 2026
Tracked Since Feb 27, 2026