CVE-2026-19744 MEDIUM

CVE-2026-19744: Stored Cross-site Scripting in Pentestify Markdown renderer via unescaped quotes

Vendor Maalfer
Product Pentestify
Weakness CWE-79 · XSS
Published August 13, 2026
Last update August 13, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N

What the vulnerability does

01Description

Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute arbitrary JavaScript in the application origin via a Markdown link whose URL contains a double quote, which closes the anchor's href attribute because the renderer's sanitization step does not escape quotes

Key dates

02Disclosure timeline

August 13, 2026 CVE published

Related vulnerabilities

04Related CVE