CVE-2026-1062CRITICAL 9.8EPSS p28.2%
CVE-2026-1062CVE-2026-1062
Description
A flaw has been found in xiweicheng TMS up to 2.28.0. This affects the function Summary of the file src/main/java/com/lhjz/portal/util/HtmlUtil.java. This manipulation of the argument url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been published and may be used.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.36% probability of exploitation · percentile 28.2% · 2026-06-19T12:03:05Z |
| Published | 2026-01-17 |
| Last modified | 2026-04-29 |
Underlying weaknesses· 1
References
- https://github.com/bkglfpp/CVE-md/blob/main/%E5%95%86%E6%88%B7%E5%95%86%E5%9F%8E%E2%80%94%E5%95%86%E5%9F%8E%E5%BC%80%E5%8F%91tms/SSRF%EF%BC%881%EF%BC%89.md
- https://github.com/bkglfpp/CVE-md/blob/main/%E5%95%86%E6%88%B7%E5%95%86%E5%9F%8E%E2%80%94%E5%95%86%E5%9F%8E%E5%BC%80%E5%8F%91tms/SSRF%EF%BC%882%EF%BC%89.md
- https://vuldb.com/?ctiid.341630
- https://vuldb.com/?id.341630
- https://vuldb.com/?submit.731241
- https://vuldb.com/?submit.731242
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Server-Side Request Forgery (SSRF)cwe-918 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.