CVE-2026-90835

Summary

A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the file Markdown.java of the component Page Content Rendering. This manipulation causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. This vulnerability only affects products that are no longer supported by the maintainer.

Affected Software

VendorProductVersion RangeStatus
michaelliaoitranswarp2.0affected
michaelliaoitranswarp2.1affected
michaelliaoitranswarp2.2affected
michaelliaoitranswarp2.3affected
michaelliaoitranswarp2.4affected
michaelliaoitranswarp2.5affected
michaelliaoitranswarp2.6affected
michaelliaoitranswarp2.7affected
michaelliaoitranswarp2.8affected
michaelliaoitranswarp2.9affected
michaelliaoitranswarp2.10affected
michaelliaoitranswarp2.11affected
michaelliaoitranswarp2.12affected
michaelliaoitranswarp2.13affected
michaelliaoitranswarp2.14affected
michaelliaoitranswarp2.15affected
michaelliaoitranswarp2.16affected
michaelliaoitranswarp2.17affected
michaelliaoitranswarp2.18affected
michaelliaoitranswarp2.19affected

Weaknesses

  • CWE-79: Cross Site Scripting
  • CWE-94: Code Injection

References