CVE-2026-82090EPSS p35.7%

CVE-2026-82090CVE-2026-82090

Description

Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM.  JavaScript code can alter the application state via native bridge methods.

Scoring

EPSS0.44% probability of exploitation · percentile 35.7% · 2026-10-05T12:00:23Z
Last modified2026-09-09
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.