Vulnerabilities
CVE-2026-27639 - Mercator vulnerable to stored XSS via unescaped Blade directives in display temp...
CVE ID : CVE-2026-27639 Published : Feb. 25, 2026, 4:16 a.m. | 29 minutes ago Description : Mercator is an open source web application designed to enable mapping of information systems. A stored Cross-Site Scripting (XSS) vulnerability exists in Mercator prior to version 2026.02.22 due to the use of unescaped Blade directives (`{!! !!}`) in display templates. An authenticated user with the User role can inject arbitrary JavaScript payloads into fields such as