CVE 5.3 MEDIUM

Juicer through 1.12.18 Stored Cross-Site Scripting via Unescaped API Response_CVE-2026-53737

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Description

Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the connected feed data can inject script that executes in an administrator's browser when the settings page loads.

Basic Information

ID CVE-2026-53737
Source VulnCheck
Published Jun 10, 2026 at 20:39

Affected Product

Vendor saas.group
Product Juicer
Affected Versions saas.group Juicer 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.