Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-3438

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Apr 08, 2026
Vendor unknown

Description

A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction.

References