VYPR
Medium severity6.1NVD Advisory· Published Apr 3, 2024· Updated Jun 17, 2026

CVE-2024-26495

CVE-2024-26495

Description

Cross Site Scripting (XSS) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the BBCode tags in the post content and post comments function.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Friendica/Friendicallm-fuzzy3 versions
    >2023.12+ 2 more
    • (no CPE)range: >2023.12
    • (no CPE)
    • cpe:2.3:a:friendica:friendica:*:*:*:*:*:*:*:*range: >=2023.12,<2024.03

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.