CVE-2026-18247EPSS p34.0%

CVE-2026-18247CVE-2026-18247

Description

A Cross Site Scripting (XSS) vulnerability in the Web Portals of AtHoc IWS in versions earlier than 7.21 HF-734 could allow an attacker to potentially execute actions in the context of the victim's session.

Scoring

EPSS0.42% probability of exploitation · percentile 34.0% · 2026-10-06T12:00:23Z
Last modified2026-09-03
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.