CVE-2026-0521 MEDIUM

CVE-2026-0521: Reflected Cross-Site Scripting in PDF Export Error Message

Weakness CWE-79 · XSS
Published February 6, 2026
Last update February 6, 2026

CVSS base score

5.6/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A reflected cross-site scripting (XSS) vulnerability in the PDF export functionality of the TYDAC AG MAP+ solution allows unauthenticated attackers to craft a malicious URL, that if visited by a victim, will execute arbitrary JavaScript in the victim's context. Such a URL could be delivered through various means, for instance, by sending a link or by tricking victims to visit a page crafted by the attacker. This issue was verified in MAP+: 3.4.0.

Key dates

02Disclosure timeline

February 6, 2026 CVE published
February 6, 2026 Record updated