VYPR
Medium severity5.4NVD Advisory· Published Apr 8, 2026· Updated Apr 17, 2026

CVE-2026-27787

CVE-2026-27787

Description

Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.

Affected products

1
  • cpe:2.3:a:icz:matcha_sns:*:*:*:*:*:*:*:*
    Range: <=1.3.9

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.