Cross-Site Scripting Vulnerability in yaojingang GEOFlow Disclosed

Cross-Site Scripting Vulnerability in yaojingang GEOFlow Disclosed

First seen 31 Aug 2026, 21:03 UTC Feedlycve.reportgithub.comvuldb.comnvd.nist.gov+1 51.0

Article Content

Browse articles
ThreatCluster

A cross-site scripting (XSS) vulnerability, CVE-2026-82664, has been identified in yaojingang GEOFlow versions up to 2.1.0, affecting the JSON-LD Theme Handler component. This vulnerability allows unauthenticated attackers to inject malicious scripts via the HomeController.php file, which can execute in the browsers of users accessing the affected page. The vulnerability can lead to session cookie theft, unauthorized actions on behalf of victims, or redirection to malicious sites. Currently, there is no public proof-of-concept or confirmed exploitation reported. Users are advised to upgrade to version 2.1.1 or later to mitigate the issue. The CVSS base score assigned to this vulnerability is 4.3, indicating a medium severity level. As an interim measure, implementing input validation and output encoding is recommended. The exploit has been publicly disclosed, and security advisories have been released.

Key Points: • CVE-2026-82664 affects yaojingang GEOFlow up to version 2.1.0. • The vulnerability allows remote cross-site scripting attacks via HomeController.php. • Users should upgrade to version 2.1.1 to mitigate the risk.

Timeline

2026-08-31
CVE-2026-82664 published
A cross-site scripting vulnerability in yaojingang GEOFlow was disclosed, affecting versions up to 2.1.0.
Feedly
2026-08-31
Public disclosure of vulnerability
The vulnerability was publicly disclosed, prompting advisories for users to upgrade to version 2.1.1.
cve.report