cvedb.io
CVE-2026-9195
CRITICAL · CVSS 9.3
EPSS exploitation probability: 0%
Published 2026-08-05T16:17:10.313 · Last modified 2026-08-05T19:17:48.113

Summary

A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture credentials, and perform privileged actions on the administrator's behalf.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.