CVE-2026-4510 | PbootCMS up to 3.2.12 Parameter MemberController.php alert_location backurl cross site scripting
A vulnerability has been found in PbootCMS up to 3.2.12 and classified as problematic. This impacts the function alert_location of the file apps/home/controller/MemberController.php of the component Parameter Handler. This manipulation of the argument backurl causes cross site scripting.
This vulnerability is registered as CVE-2026-4510. Remote exploitation of the attack is possible. Furthermore, an exploit is available.