CVE-2026-5217 - Optimole <= 4.2.2 - Unauthenticated Stored Cross-Site Scripting via Srcset Descriptor Parameter
CVE ID :CVE-2026-5217
Published : April 11, 2026, 2:16 a.m. | 13 hours, 57 minutes ago
Description :The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimizatio...
Related Vulnerabilities
- CVE-2026-29861: PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the use CRITICAL
- CVE-2026-29002: CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users t HIGH
- CVE-2026-40100: FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool end MEDIUM
- CVE-2026-1263: The Webling plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, MEDIUM
- CVE-2026-33618: Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController HIGH
Related Coverage
Threat Actors