CVE-2026-37710

Published: Ago 28, 2026 Last Modified: Ago 28, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote attacker to execute arbitrary code via the site navigation custom URL function

https://github.com/omeka/omeka-s
https://github.com/omeka/omeka-s/commit/8d47b0ef2dfabc1dd8c52893400321d1fbb5b5f4
https://github.com/raav3n/vulnerability-research/blob/main/CVE-2026-37710/READM…