CVE-2026-4495 | atjiu pybbs 6.0.0 CommentApiController.java create cross site scripting (EUVD-2026-13758)
A vulnerability was found in atjiu pybbs 6.0.0 and classified as problematic. This impacts the function create of the file src/main/java/co/yiiu/pybbs/controller/api/CommentApiController.java. The manipulation results in cross site scripting.
This vulnerability is known as CVE-2026-4495. It is possible to launch the attack remotely. Furthermore, an exploit is available.