VYPR

qt6-base

by Qt

CVEs (1)

  • CVE-2026-15037Jul 25, 2026
    risk 0.00cvss epss

    Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are…