Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.1
UDesign: Malicious Code Can Run in Your Browser
CVE-2026-28130
Summary
Some versions of UDesign allow attackers to inject malicious code into your website, potentially stealing sensitive information or taking control of your account. This issue affects UDesign versions up to 4.14.0. Update to a fixed version to protect your website and users.
Original title
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AndonDesign UDesign u-design allows Reflected XSS.This issue affects UDesign: from n/a through ...
Original description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AndonDesign UDesign u-design allows Reflected XSS.This issue affects UDesign: from n/a through <= 4.14.0.
nvd CVSS3.1
7.1
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
Published: 5 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026