CVE-2026-27787EPSS p14.3%

CVE-2026-27787CVE-2026-27787

icz / matcha_sns

Description

Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.

Scoring

CVSS 5.4 ()
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS0.24% probability of exploitation · percentile 14.3% · 2026-10-06T12:00:23Z
Last modified2026-07-25
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.