Description
A vulnerability was found in stephen-kruger bluebox up to 4.5.12. Affected by this vulnerability is an unknown functionality. Performing a manipulation of the argument code results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report.
References (7)
Core 7
Core References
Third Party Advisory third-party-advisory
CVE-2026-14704 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-14704
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-376300 | stephen-kruger bluebox cross site scripting
https://vuldb.com/vuln/376300
Signature, Permissions Required signature
permissions-required
VDB-376300 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/376300/cti
Third Party Advisory third-party-advisory
Submit #847357 | Bluebox BlueBox V4.5.12 Cross Site Scripting
https://vuldb.com/submit/847357
Issue Tracking issue-tracking
https://github.com/stephen-kruger/bluebox/issues/32
Exploit exploit
issue-tracking
https://github.com/stephen-kruger/bluebox/issues/32#issuecomment-4632135192
Product product
https://github.com/stephen-kruger/bluebox/
Scores
CVSS v3
4.3
EPSS
0.0029
EPSS Percentile
21.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-79
CWE-94
Status
published
Products (13)
stephen-kruger/bluebox
4.5.0
stephen-kruger/bluebox
4.5.1
stephen-kruger/bluebox
4.5.10
stephen-kruger/bluebox
4.5.11
stephen-kruger/bluebox
4.5.12
stephen-kruger/bluebox
4.5.2
stephen-kruger/bluebox
4.5.3
stephen-kruger/bluebox
4.5.4
stephen-kruger/bluebox
4.5.5
stephen-kruger/bluebox
4.5.6
... and 3 more
Published
Jul 05, 2026
Tracked Since
Jul 05, 2026