Unrated severityNVD Advisory· Published Mar 25, 2026· Updated Mar 26, 2026
Kiteworks Secure Data Forms vulnerable to Cross-site Scripting
CVE-2026-24750
Description
Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, an authenticated attacker could exploit an Improper Neutralization of Input During Web Page Generation as Stored XSS when modifying forms. Upgrade Kiteworks to version 9.2.1 or later to receive a patch.
Affected products
2<9.2.1+ 1 more
- (no CPE)range: <9.2.1
- (no CPE)range: < 9.2.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/kiteworks/security-advisories/security/advisories/GHSA-rfwm-2hq6-h84gmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.