CVE-2026-23900 encompasses multiple stored cross-site scripting (XSS) vulnerabilities discovered in the maps and icon rendering logic of the Phoca Maps component, affecting versions 5.0.0 through 6.0.2. These vulnerabilities allow attackers to inject malicious scripts that persist in the application's data storage. The vulnerability is classified as MEDIUM severity with a CVSS score of 6.5, indicating moderate risk with potential for confidentiality and integrity compromise. The attack requires no authentication or user interaction and can be executed over the network through a straightforward approach. Based on current threat intelligence, this vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog and demonstrates negligible exploitation activity in the wild, though organizations using affected Phoca Maps versions should prioritize patching to versions beyond 6.0.2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0.0, <= 6.0.2CPE matchmatch criteria | cpe:2.3:a:phoca:maps:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.