CVE-2026-78838
NONE—CVSS v3
—CVSS v2
—
EPSS (exploit probability)
—CWE
Description
A reflected cross-site scripting (XSS) vulnerability in the grid_datasource.php component of AppNitro MachForm v30 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted payload into the filter[filters][0][field] parameter.
Affected routers (0)
No routers currently mapped to this CVE in our database.