Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 28 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Omeka S Navigation XSS Enables Arbitrary Code Execution | |
| Weaknesses | CWE-79 |
Fri, 28 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Omeka
Omeka omeka S |
|
| Vendors & Products |
Omeka
Omeka omeka S |
Fri, 28 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote attacker to execute arbitrary code via the site navigation custom URL function | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-28T14:11:30.481Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-37710
No data.
Status : Received
Published: 2026-08-28T16:17:46.423
Modified: 2026-08-28T16:17:46.423
Link: CVE-2026-37710
No data.
OpenCVE Enrichment
Updated: 2026-08-28T17:30:08Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')