Reflected Cross-Site Scripting
CVE:
CVE-2026-55730
Product: Loytec / LWEB-802
Severity: High 8.7
Published: 24.07.2026
Advisory:
Read the advisory
Loytec LWEB-802 before 5.0.8 fails to neutralise the project and mspParams request parameters before reflecting them into the generated page (CWE-79, CWE-116). An unauthenticated remote attacker can execute arbitrary JavaScript in a victim’s browser via a crafted link and thereby perform actions with the victim’s privileges.