CVE-2026-4186 details a cross-site scripting (XSS) vulnerability in UEditor versions up to 1.4.3.2, specifically within the JSONP Callback Handler of `php/controller.php?action=uploadimage`, affecting only unsupported product versions. Rated with a CVSS score of 3.5 (Low), exploitation requires low privileges and user interaction, can be initiated remotely, and results in a low impact on integrity. Although the exploit has been publicly disclosed, there is no evidence of active exploitation, nor are there readily available exploits in common frameworks or tools, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | UEditor | 1.4.3.0, 1.4.3.1, 1.4.3.2CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.