Medium severity6.1NVD Advisory· Published Mar 26, 2026· Updated May 7, 2026
CVE-2026-29969
CVE-2026-29969
Description
A cross-site scripting (XSS) vulnerability in the wff_cols_pref.css.aspx endpoint of staffwiki v7.0.1.19219 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted HTTP request.
Affected products
2- cpe:2.3:a:workflowfirst:staffwiki:7.0.1.19219:*:*:*:*:*:*:*
- staffwiki/staffwikidescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/cmoncrook/Security-Advisories/blob/main/cve-2026-29969nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.