CVE-2026-55730EPSS p47.2%
CVE-2026-55730CVE-2026-55730
Description
Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's browser and perform actions with the victim's privileges via a crafted link containing a malicious `project` or `mspParams` parameter.
Scoring
| EPSS | 0.61% probability of exploitation · percentile 47.2% · 2026-10-06T12:00:23Z |
| Last modified | 2026-07-27 |