Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2026-23841— Movary vulnerable to Cross-site Scripting with `?categoryCreated=` param

CVSS 9.3 · Critical EPSS 0.13% · P32
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-23841

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Movary vulnerable to Cross-site Scripting with `?categoryCreated=` param
Source: NVD (National Vulnerability Database)
Vulnerability Description
Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-site scripting payloads in versions prior to 0.70.0. The vulnerable parameter is `?categoryCreated=`. Version 0.70.0 fixes the issue.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
输入验证不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Movary 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Movary是Lee Peuker个人开发者的一个影评程序。 Movary 0.70.0之前版本存在跨站脚本漏洞,该漏洞源于对categoryCreated参数输入验证不足,可能导致跨站脚本攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
leepeukermovary < 0.70.0 -

II. Public POCs for CVE-2026-23841

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-23841

登录查看更多情报信息。

Same Patch Batch · leepeuker · 2026-01-19 · 3 CVEs total

CVE-2026-238399.3 CRITICALMovary vulnerable to Cross-site Scripting with `?categoryUpdated=` param
CVE-2026-238409.3 CRITICALMovary vulnerable to Cross-site Scripting with `?categoryDeleted=` param

IV. Related Vulnerabilities

V. Comments for CVE-2026-23841

No comments yet


Leave a comment