CVE-2026-81814EPSS p31.5%
CVE-2026-81814CVE-2026-81814
Description
Affected versions of Flowintel render calendar event titles using innerHTML. Because those titles are derived from case titles, a user able to create or modify a case title could store HTML or script-capable content that is later interpreted by the browser when another user views the calendar.
The fix changes:
titleEl.innerHTML = arg.event.title
to:
titleEl.textContent = arg.event.title || ''
and similarly stops using innerHTML for the static download icon.
Version impacted =>3.3.0
Scoring
| EPSS | 0.40% probability of exploitation · percentile 31.5% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-28 |