Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.1
Musico Software Allows Hackers to Inject Malicious Code via Reflected XSS
CVE-2026-27367
Summary
Some versions of the Musico software are vulnerable to a security issue that allows hackers to inject malicious code into web pages, potentially stealing user data or taking control of user sessions. This affects users who visit the Musico website, so it's essential to upgrade to the latest version. Update to Musico 3.2.5 or later to fix this issue.
Original title
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Musico musico allows Reflected XSS.This issue affects Musico: from n/a through <= 3....
Original description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Musico musico allows Reflected XSS.This issue affects Musico: from n/a through <= 3.2.4.
nvd CVSS3.1
7.1
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
Published: 5 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026