CVE 9.3 CRITICAL

Movary vulnerable to Cross-site Scripting with `?categoryDeleted=` param_CVE-2026-23840

9.3 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Description

Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-site scripting payloads in versions prior to 0.70.0. The vulnerable parameter is `?categoryDeleted=`. Version 0.70.0 fixes the issue.

AI Analysis

Cross-site scripting vulnerability due to insufficient input validation in Movary

Basic Information

ID CVE-2026-23840
Source GitHub_M
Published Jan 19, 2026 at 18:32

Affected Product

Vendor leepeuker
Product movary
Version < 0.70.0
Affected Versions leepeuker movary < 0.70.0

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor leepeuker
Product Movary
Version < 0.70.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.