Frequency
2
occurrences
First Seen
April 17, 2026
Last Seen
April 18, 2026
Related Threat Clusters
-
CVE-2026-6493: XSS Vulnerability in lukevella rallly Affects Password Reset Functionality
A cross-site scripting (XSS) vulnerability, identified as CVE-2026-6493, has been discovered in lukevella rallly versions up to 4.7.4. The flaw resides in the Reset Password Handler component, specifically in the…
2 articles · Updated April 18, 2026
Recent Intelligence Reports
- CVE-2026-6493: lukevella rallly Reset Password reset-password-form.tsx cross site scripting [LOW] CVSS 3.5 Exploit Intelligence — Recent CVEs / 23h A flaw has been found in lukevella rallly up to 4.7.4. This affects an unknown function of the file apps/web/src/app/[locale]/(auth)/reset-password/components/reset-password-form.tsx of the component Reset Password Handler. Executing a manipulation of the argument redirectTo can lead to cross site s — exploit-intel.com · April 18, 2026
- CVE-2026-6493 - Exploits & Severity — Feedly · April 17, 2026