9.3
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Description
Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-site scripting payloads in versions prior to 0.70.0. The vulnerable parameter is `?categoryDeleted=`. Version 0.70.0 fixes the issue.
AI Analysis
Cross-site scripting vulnerability due to insufficient input validation in Movary
Basic Information
ID
CVE-2026-23840
Source
GitHub_M
Published
Jan 19, 2026 at 18:32
Affected Product
Vendor
leepeuker
Product
movary
Version
< 0.70.0
Affected Versions
leepeuker movary < 0.70.0
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
leepeuker
Product
Movary
Version
< 0.70.0