Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35169

24
FAUCET Score

CVE-2026-35169 is a reflected cross-site scripting vulnerability in the help_editor module of LORIS (Longitudinal Online Research and Imaging System), a self-hosted web application used for neuroimaging research data and project management. The flaw stems from improper sanitization of user-supplied variables in versions prior to 27.0.3 and 28.0.1. The same input vector also permits unauthorized download of arbitrary markdown files from affected servers. The vulnerability has a CVSS v3.1 score of 5.4 (Medium severity) with network-based attack vector and low attack complexity, but requires user interaction and authenticated access. The attack has limited impact, affecting confidentiality and integrity but not availability. The vulnerability represents a moderate risk requiring low privileges and social engineering to exploit through a malicious link. There is no evidence of active exploitation. The vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and is not featured on the Hot List, indicating minimal community attention and no publicly available exploit code. The EPSS score of 0.00033 suggests very low probability of exploitation in the wild. Organizations running LORIS should prioritize patching to versions 27.0.3 or 28.0.1 as part of routine maintenance.

Impacted Technologies

VendorProductVersion(s)CPE
>= 15.10, <= 27.0.2CPE matchmatch criteria
cpe:2.3:a:mcgill:loris:*:*:*:*:*:*:*:*
28.0.0CPE matchmatch criteria
cpe:2.3:a:mcgill:loris:28.0.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.7HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.3
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 3rd percentile among its peer group of 15,224 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryvendor investigatingvia nvd_reference
View patch

References

github.com / aces/Loris/security/advisories/GHSA-j2p3-58m2-v6q3
Vendor Advisory