Back

HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in coolercontrol-ui

Published Apr 8, 2026

Description

Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the service via malicious JavaScript in poisoned log entries

Affected products

Remediation

Vendor solution

Upgrade to version 4.0.0

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Apr 8, 2026
Updated Apr 8, 2026
Reserved Apr 1, 2026
CISA Vulnrichment
Updated Apr 8, 2026
NVD
Status Analyzed
Modified Jul 24, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitLab
Published Apr 8, 2026
Updated Apr 8, 2026
Exploited since n/a
EUVD-2026-20459