Cross-Site Scripting (xss) - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
15
occurrences
First Seen
November 27, 2025
Last Seen
August 20, 2026

Related Threat Clusters

Recent Intelligence Reports

  • SVD-2026-0804: Security Hardening Release for Splunk SOAR - August 2026 Splunk Security Announcements / 19h In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the Representational State Transfer (REST) API and execute arbitrary code. In Splunk SOAR versions below 8.6.0, a user who holds the Administrator role could use path traversal in the Universal Forwarder installer’s archive extraction to write files outside the intended inst — advisory.splunk.com · August 20, 2026
  • 74 — cwe.mitre.org · August 17, 2026
  • Microsoft open — Feeds.4Sysops · July 20, 2026
  • Cve 2026 22752 — spring.io · July 18, 2026
  • Thousands of MCP Servers Found Vulnerable to File Access and Injection Attacks — Gbhackers · July 7, 2026
  • pgAdmin 4 Released with Patches for Seven Vulnerabilities and Feature Enhancements — Gbhackers · June 22, 2026
  • How Hackers Operate: The Tools Behind Real — Analyticsinsight · June 21, 2026
  • SAP fixes critical flaws in NetWeaver and Commerce Cloud — Bleepingcomputer · June 9, 2026

CVSS v3.1 Breakdown