CVE-2026-5217 - Optimole <= 4.2.2 - Unauthenticated Stored Cross-Site Scripting via Srcset Descriptor Parameter
CVE ID :CVE-2026-5217
Published : April 11, 2026, 2:16 a.m. | 13 hours, 57 minutes ago
Description :The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimizatio...
Related Vulnerabilities
- CVE-2026-35668: OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sa HIGH
- CVE-2026-32894: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Obj HIGH
- CVE-2026-33698: Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise N/A
- CVE-2025-58920: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i HIGH
- CVE-2026-23782: An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allow HIGH
Related Coverage
Threat Actors