CVE · Medium

CVE-2026-22191 — Comments – wpDiscuz [wpdiscuz] < 7.6.47

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-22191 Comments – wpDiscuz [wpdiscuz] < 7.6.47 Improper Neutralization of Special Elements Used in a Template Engine Medium 5.2 < 7.6.47 7.6.47 2026-03-13

CVE-2026-22191

Beghelli Sicuro24 SicuroWeb is vulnerable to a template injection flaw that lets attackers inject malicious AngularJS expressions by exploiting improper handling of untrusted input. This can lead to arbitrary JavaScript execution, particularly when the application uses the AngularJS 1.5.2 runtime and operates over plaintext HTTP connections, allowing network-adjacent attackers to deliver harmful payloads through MITM attacks.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.