VYPR
Low severity3.5NVD Advisory· Published Mar 20, 2026· Updated Jun 17, 2026

CVE-2026-4494

CVE-2026-4494

Description

A vulnerability was identified in atjiu pybbs 6.0.0. This affects the function create of the file src/main/java/co/yiiu/pybbs/controller/api/TopicApiController.java. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

Affected products

2
  • atjiu/Pybbsinferred2 versions
    =6.0.0+ 1 more
    • (no CPE)range: =6.0.0
    • (no CPE)range: =6.0.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.