Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32774

18
FAUCET Score

CVE-2026-32774 describes a stored cross-site scripting (XSS) vulnerability in Vulnogram 1.0.0, specifically within its comment hypertext handling. This flaw enables remote attackers to inject malicious JavaScript payloads through comments, which are then executed in victims' browsers. With a CVSS score of 5.4 (Medium), exploitation requires low privileges and user interaction, potentially leading to session hijacking or data theft. There is currently no evidence of active exploitation (KEV: No), nor are public exploit modules available; community discussion and media coverage remain minimal.

Impacted Technologies

VendorProductVersion(s)CPE
1.0.0CPE matchmatch criteria
cpe:2.3:a:vulnogram:vulnogram:1.0.0:beta1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.3MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
LOW
SS Integrity
LOW
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.28%
Probability of exploitation in next 30 days
EPSS Percentile
19.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0028 is in the 27th percentile among its peer group of 15,224 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

npmGHSA-vggc-6pg2-xvp9medium

Vulnogram contains a stored cross-site scripting vulnerability in comment hypertext handling

Mar 16, 2026

References

github.com / Vulnogram/Vulnogram/commit/2f0e21b113c58124084c7b74c9768fc241126a05
Patch
github.com / Vulnogram/Vulnogram
Product
github.com / Vulnogram/Vulnogram/security/advisories/GHSA-pg4p-2985-gvxr
Broken Link
vulncheck.com / advisories/vulnogram-stored-cross-site-scripting-via-comment-hypertext
Third Party Advisory