What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pascal Birchler Preferred Languages allows DOM-Based XSS.This issue affects Preferred Languages: from n/a through 2.2.2.
Explanation of Vulnerability in Simple Terms
02Summary
Preferred Languages versions up to 2.2.2 contain a cross-site scripting vulnerability that allows high-privilege users to inject malicious scripts. The vulnerability requires user interaction and affects the integrity and confidentiality of site data. An attacker with administrative access can craft a malicious request that, when clicked by another user, executes JavaScript in their browser.
What an attacker can do
03Attacker Capabilities
Inject and execute malicious JavaScript in other users' browsers to steal data or perform actions on their behalf.
Potential impact on your site
04Site Impact
An admin-level attacker can compromise other users' sessions or steal sensitive information through JavaScript execution.
Conditions required to exploit
05Prerequisites
Attacker must have high-level site privileges (e.g., admin or editor role) and trick another user into clicking a malicious link.
Key dates
06Disclosure timeline
March 6, 2026
CVE published
April 28, 2026
Record updated