CVE-2026-5253 identifies a Cross-Site Scripting (XSS) vulnerability in bufanyun HotGo versions 1.0 and 2.0, specifically affecting the editNotice Endpoint within the MessageList.vue component. With a CVSS score of 3.5 (LOW), this weakness allows for remote exploitation with low attack complexity and privileges, though it requires user interaction to achieve a low integrity impact. Public exploit code for this vulnerability is available, yet there is no indication of active exploitation, and it is not present in CISA's Known Exploited Vulnerabilities catalog. Community discussion and media coverage remain minimal, suggesting low public awareness despite the vendor's lack of response to the disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Bufanyun | HotGo | 1.0, 2.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.