CVE Feed

    Dashboard / CVE / CVE-2026-4313

    CVE-2026-4313

    AdaptiveGRC is vulnerable to Stored XSS via text type fields across the forms. Authenticated attacker can replace the value of the text field in the HTTP POST request. Improper parameter validation by the server results in arbitrary JavaScript execution in the victim's browser. Critically, this may allow the attacker to obtain the administrator authentication token and perform arbitrary actions with administrative privileges, which could lead to further compromise. This issue occurs in versions released before December 2025.

    Published:Apr 24, 2026
    Last Modified:Apr 28, 2026
    EPS:Apr 24, 2026
    EPSS Score:0.00025
    CVSS Score:2.4

    Affected Products

    Vendor
    C&f
    Product
    Adaptivegrc

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High