CVE-2026-5010

MEDIUM

Reflected Cross-Site Scripting (XSS) in Sanoma’s Clickedu

Title source: cna
STIX 2.1

Description

A reflected Cross-Site Scripting (XSS) vulnerability has been discovered in Clickedu. This vulnerability allows an attacker to execute JavaScript code in the victim’s browser by sending them a malicious URL using the endpoint “/user.php/”. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on the user’s behalf.

Scores

CVSS v4 5.1
EPSS 0.0027
EPSS Percentile 18.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
Sanoma/Clickedu < 5.1
Sanoma/Clickedu 5.1
Published Mar 27, 2026
Tracked Since Mar 29, 2026