CVE-2026-15928

Summary

XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.

Affected Software

VendorProductVersion RangeStatus
XMLRPC-CXMLRPC-C1.07 <= 1.67.01affected
XMLRPC-CXMLRPC-C1.07 <= 1.64.03affected

Weaknesses

  • CWE-79: CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')

References