MEDIUM 4.3 NVD

CVE-2026-102090

Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-con

Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate application domain. This could increase the credibility of phishing attempts relying on malicious links embedded in the displayed content.

References

Published: 2026-09-30 · Source: NVD · Feed updated: 2026-10-01
This medium severity vulnerability with a CVSS score of 4.3 was published on 2026-09-30 via NVD.
vulnfeed aggregates 9519 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.