Threats Tagged 'cve-2026-30048'
View all threats tagged with 'cve-2026-30048'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-30048'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-30048 is a stored cross-site scripting (XSS) vulnerability affecting the NotChatbot WebChat widget up to version 1.4.4. The vulnerability arises because user input is not properly sanitized before being stored and rendered in the chat conversation history, allowing attackers to inject arbitrary JavaScript code. This malicious code executes when the chat history is reloaded, potentially compromising users who view the chat. The issue is inherent to the widget itself and not dependent on specific website configurations. The vulnerability has a CVSS score of 5.4 (medium severity), requires low privileges and user interaction, and impacts confidentiality and integrity but not availability. No known exploits are currently reported in the wild. Organizations using this widget should prioritize input validation and consider patching or replacing the widget to mitigate risk. Join the discussion | CVE Database V5 | 03/18/2026, 00:00:00 UTC Added: 03/18/2026, 17:28:27 UTC |
Showing 1 to 1 of 1 result