CVE-2026-5253

LOW

bufanyun HotGo editNotice Endpoint MessageList.vue cross site scripting

Title source: cna
STIX 2.1

Description

A weakness has been identified in bufanyun HotGo 1.0/2.0. Affected by this vulnerability is an unknown functionality of the file /web/src/layout/components/Header/MessageList.vue of the component editNotice Endpoint. Executing a manipulation can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Vdb Entry vdb-entry
VDB-354443 | bufanyun HotGo editNotice Endpoint MessageList.vue cross site scripting
https://vuldb.com/vuln/354443
Signature, Permissions Required signature permissions-required
VDB-354443 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/354443/cti
Third Party Advisory third-party-advisory
Submit #780614 | bufanyun HotGo <= v2.0 Cross Site Scripting
https://vuldb.com/submit/780614

Scores

CVSS v3 3.5
EPSS 0.0003
EPSS Percentile 9.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79 CWE-94
Status published
Products (2)
bufanyun/HotGo 1.0
bufanyun/HotGo 2.0
Published Apr 01, 2026
Tracked Since Apr 01, 2026