CVE-2026-53737
MEDIUMJuicer through 1.12.18 Stored Cross-Site Scripting via Unescaped API Response
Title source: cnaDescription
Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the connected feed data can inject script that executes in an administrator's browser when the settings page loads.
References (2)
Core 2
Core References
Third Party Advisory third-party-advisory
VulnCheck Advisory: Juicer through 1.12.18 Stored Cross-Site Scripting via Unescaped API Response
https://www.vulncheck.com/advisories/juicer-through-stored-cross-site-scripting-via-unescaped-api-response
Scores
CVSS v3
6.1
EPSS
0.0016
EPSS Percentile
5.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (1)
saas.group/Juicer
< 1.12.18
Published
Jun 10, 2026
Tracked Since
Jun 11, 2026