CVE-2026-1062CRITICAL 9.8EPSS p28.2%

CVE-2026-1062CVE-2026-1062

Description

A flaw has been found in xiweicheng TMS up to 2.28.0. This affects the function Summary of the file src/main/java/com/lhjz/portal/util/HtmlUtil.java. This manipulation of the argument url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been published and may be used.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.36% probability of exploitation · percentile 28.2% · 2026-06-19T12:03:05Z
Published2026-01-17
Last modified2026-04-29

Underlying weaknesses· 1

CWE-918

References

  1. https://github.com/bkglfpp/CVE-md/blob/main/%E5%95%86%E6%88%B7%E5%95%86%E5%9F%8E%E2%80%94%E5%95%86%E5%9F%8E%E5%BC%80%E5%8F%91tms/SSRF%EF%BC%881%EF%BC%89.md
  2. https://github.com/bkglfpp/CVE-md/blob/main/%E5%95%86%E6%88%B7%E5%95%86%E5%9F%8E%E2%80%94%E5%95%86%E5%9F%8E%E5%BC%80%E5%8F%91tms/SSRF%EF%BC%882%EF%BC%89.md
  3. https://vuldb.com/?ctiid.341630
  4. https://vuldb.com/?id.341630
  5. https://vuldb.com/?submit.731241
  6. https://vuldb.com/?submit.731242

1

TypeTargetConfidenceTier
WeaknessServer-Side Request Forgery (SSRF)cwe-9180%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-1061
CVE
CVE-2026-2682
CVE
CVE-2026-11469
CVE
CVE-2025-8228
CVE
CVE-2025-5132
CVE
CVE-2025-2997
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.