Maalfer
Maalfer Pentestify: vulnerabilities and CVEs
Maalfer Pentestify has 6 published vulnerabilities, 6 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs6
Last 12 months6
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-76203 | Medium (5.1) | 0.40% | — | Aug 19, 2026 | Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer in maalfer Pentestify 1.2.0 through 2.3.2 allows an authenticated user to force outbound HTTP requests from other users' browsers,… |
| CVE-2026-19744 | Medium (5.1) | 0.47% | — | Aug 13, 2026 | Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute arbitrary JavaScript in the application origin via a Markdown link whose URL contains a double… |
| CVE-2026-19716 | Medium (5.1) | 0.47% | — | Aug 13, 2026 | Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authenticated attacker to execute arbitrary JavaScript in the browser of another authenticated user via… |
| CVE-2026-19434 | Medium (5.1) | 0.47% | — | Aug 11, 2026 | Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the application origin via HTML markup stored in a finding's severity field,… |
| CVE-2026-59231 | Medium (5.3) | 0.45% | — | Jul 31, 2026 | Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server to arbitrary attacker-chosen destinations via… |
| CVE-2026-59238 | Medium (6.9) | 0.56% | — | Jul 20, 2026 | Stored Cross-site Scripting (CWE-79) in the client-side report rendering functions (renderPreview, renderEditor, renderAuditData in js/app.js) in maalfer Pentestify before 1.1.0 allows a remote, authenticated attacker… |