CVE-2026-24903 - OrcaStatLLM Researcher Stored Cross-Site Scripting (XSS) via Log Message Injecti...

CVE-2026-24903 - OrcaStatLLM Researcher Stored Cross-Site Scripting (XSS) via Log Message Injecti...

CVE ID : CVE-2026-24903 Published : Feb. 6, 2026, 6:15 p.m. | 27 minutes ago Description : OrcaStatLLM Researcher is an LLM Based Research Paper Generator. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Log Message in the Session Page in OrcaStatLLM-Researcher that allows attackers to inject and execute arbitrary JavaScript code in victims' browsers through malicious research topic inputs. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Feb. 6, 2026
Impact: XSS