Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.1
ThemeGoods Architecturer allows malicious scripts to be injected into web pages
CVE-2026-27358
Summary
A security issue in ThemeGoods Architecturer means that if an attacker tricks a user into clicking a malicious link, they could inject malicious code into a web page. This could potentially allow them to access sensitive information or take control of the user's account. Users should update to Architecturer 3.8.9 or later to fix the issue.
Original title
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Architecturer architecturer allows Reflected XSS.This issue affects Architecturer: f...
Original description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Architecturer architecturer allows Reflected XSS.This issue affects Architecturer: from n/a through <= 3.8.8.
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
Published: 5 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026