CVE-2026-66694: Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-66694
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-66694 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Unauthenticated Cross Site
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-66707: Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.nvd · 2026-08-06
- highCVE-2026-66705: Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.nvd · 2026-08-06
- highCVE-2026-66702: Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.nvd · 2026-08-06
- highCVE-2026-66690: Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.nvd · 2026-08-06
- mediumCVE-2026-66686: Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Clean…nvd · 2026-08-06
- mediumCVE-2026-66681: Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions.nvd · 2026-08-06
More from NVD Recent CVEs
- highCVE-2026-8325: A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds …2026-08-06
- highCVE-2026-7867: A flaw was found in udisks2. A local attacker with an active console session can exploit insuff…2026-08-06
- highCVE-2026-7406: A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untr…2026-08-06
- mediumCVE-2026-7405: A maliciously crafted TIF file, when parsed through certain Autodesk products during image impo…2026-08-06
- mediumCVE-2026-71555: PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.…2026-08-06