{"ok":true,"trend":{"id":535088,"platform":"mastodon","region":"global","key":"🚨 cve-2026-102147 — cvss 9.3 critical a stored cross-site scripting (xss) weakness in kiteworks core could allow an unau","title":"🚨 CVE-2026-102147 — CVSS 9.3 CRITICAL A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unau","url":"https://mastodon.social/@stemshop/117362273008155315","first_seen":"2026-09-30T22:28:07.063619Z","last_seen":"2026-09-30T22:28:07.063619Z","last_rank":8,"peak_rank":8,"last_volume":0,"peak_volume":0,"seen_count":1,"score":0.7934375,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"Security researchers are flagging CVE-2026-102147, a critical vulnerability in Kiteworks Core carrying a CVSS score of 9.3. The flaw is a stored cross-site scripting weakness that could let an unauthenticated attacker plant crafted content which then executes arbitrary JavaScript in the session of an administrator who views it, potentially giving attackers privileged access. Organizations running Kiteworks are urged to review the advisory and apply patches.","why":"System administrators and security teams are spreading alerts about a newly disclosed critical flaw that could compromise admin sessions in widely used secure file-sharing software.","tone":"neutral","entities":["Kiteworks","CVE-2026-102147"],"summarized_at":"2026-09-30T22:29:46.841504Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":2049},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Critical stored XSS flaw reported in Kiteworks Core","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-09-30T22:28:07.063619Z","rank":8,"volume":0}],"posts":[{"platform":"mastodon","url":"https://mastodon.social/@stemshop/117362273008155315","author":"stemshop","title":null,"snippet":"🚨 CVE-2026-102147 — CVSS 9.3 CRITICAL A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator who views the affected…","posted_at":"2026-09-30T22:09:27.729000Z","likes":0}],"elsewhere":[],"window":"7d"}}