Ghostwire

CVE-2026-4313: AdaptiveGRC is vulnerable to Stored XSS via text type fields across the forms. Authenticated attacker can replace the...

MEDIUM CVSS 0.0 Exploit Available

Published: April 24, 2026 | Last Modified: April 24, 2026

Description

AdaptiveGRC is vulnerable to Stored XSS via text type fields across the forms. Authenticated attacker can replace the value of the text field in the HTTP POST request. Improper parameter validation by the server results in arbitrary JavaScript execution in the victim's browser. Critically, this may allow the attacker to obtain the administrator authentication token and perform arbitrary actions with administrative privileges, which could lead to further compromise. This issue occurs in versions released before December 2025.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (2 articles)

References