CVE-2026-15928

Reflected Cross-site Scripting (XSS) in XMLRPC-C Library

Discovered by Andrew Bick on behalf of The Missing Link Security

Vulnerability Details

 XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component. Under specific conditions, this may allow an adversary to hijack a victim user’s session and perform actions in their security context.

Affected Versions

Affected Versions
1.07 to 1.67.01 (Advanced and Stable branches)

1.07 to 1.64.03 (Super Stable branch)

Fixed Versions

Fixed Versions
1.67.02 (Advanced and Stable branches)

1.64.04 (Super Stable branch)

Latest News