CVE-2026-15928 PUBLISHED

Assigner: TML
Reserved: 16.07.2026 Published: 27.07.2026 Updated: 27.07.2026

XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
CVSS Score: 8.2

Product Status

Vendor XMLRPC-C
Product XMLRPC-C
Versions Default: unaffected
  • affected from 1.07 to 1.67.01 (incl.)
  • affected from 1.07 to 1.64.03 (incl.)

Credits

  • Andrew Bick at The Missing Link Security finder

References

Problem Types

  • CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') CWE

Impacts

  • CAPEC-63 Cross-Site Scripting (XSS)