CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-69092

mediumCVSS 6.5covered by 1 sourcefirst seen 2026-08-03
Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echoes unencoded exception messages to the HTTP response. Unauthenticated attackers can inject arbitrary JavaScript through SAML Issuer elements or LightSaml library parameters to execute code in users' browsers and hijack sessions.

⚡ Watch CVE-2026-69092

Get an email if CVE-2026-69092 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-69092

CVE.org record

Embed the live status

CVE-2026-69092 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-69092 status](https://www.csirts.com/badge/CVE-2026-69092)](https://www.csirts.com/cve/CVE-2026-69092)