5.1
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
Description
HTML injection vulnerability in multiple Botble products such as TransP, Athena, Martfury, and Homzen, consisting of an HTML injection due to a lack of proper validation of user input by sending a request to '/search' using the 'q' parameter.
Basic Information
ID
CVE-2026-1183
Source
INCIBE
Published
Jan 20, 2026 at 12:09
Affected Product
Vendor
Botble
Product
TransP
Version
all versions
Affected Versions
Botble TransP all versions
Botble Athena all versions
Botble Martfury all versions
Botble Homzen all versions
Botble Athena all versions
Botble Martfury all versions
Botble Homzen all versions