CVE-2026-5217 - Optimole <= 4.2.2 - Unauthenticated Stored Cross-Site Scripting via Srcset Descriptor Parameter
CVE ID :CVE-2026-5217
Published : April 11, 2026, 2:16 a.m. | 13 hours, 57 minutes ago
Description :The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimizatio...
Related Vulnerabilities
- CVE-2026-36236: SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php vi CRITICAL
- CVE-2026-3498: The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clien MEDIUM
- CVE-2026-36233: A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Onl CRITICAL
- CVE-2026-5207: The LifterLMS plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all v MEDIUM
- CVE-2025-58920: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i HIGH
Related Coverage
Threat Actors