CVE-2026-78838

NONE
CVSS v3
CVSS v2
EPSS (exploit probability)
CWE

Description

A reflected cross-site scripting (XSS) vulnerability in the grid_datasource.php component of AppNitro MachForm v30 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted payload into the filter[filters][0][field] parameter.

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references