Medium severity5.7NVD Advisory· Published Mar 27, 2026· Updated Apr 8, 2026
CVE-2026-33739
CVE-2026-33739
Description
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.1812, the listing tables on multiple management pages (Host, Storage, Group, Image, Printer, Snapin) are vulnerable to Stored Cross-Site Scripting (XSS), due to insufficient server-side parameter sanitization in record creations/updates and a lack of HTML escaping in listing tables. Version 1.5.10.1812 patches the issue.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/FOGProject/fogproject/security/advisories/GHSA-8m2f-4x7g-p8f3nvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.