CVE-2026-44259

MEDIUM

efw4.X: Stored XSS via previewServlet

Title source: cna
STIX 2.1

Description

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the previewServlet serves files with their detected MIME type based on file extension, without any content sanitization or security headers. Files with .html, .htm, or .svg extensions are served as text/html or image/svg+xml respectively, causing any embedded JavaScript to execute in the victim's browser within the application's origin. This vulnerability is fixed in 4.08.010.

References (1)

Core 1
Core References

Scores

CVSS v3 4.6
EPSS 0.0014
EPSS Percentile 3.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-80
Status published
Products (1)
efwGrp/efw4.X < 4.08.010
Published May 12, 2026
Tracked Since May 13, 2026