Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-38472

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 GazellePW(GazellePosterWall)commit 86c4bedf727691b5a97af42a4864869d18446449 中,存在一个存储型跨站脚本(Stored XSS)漏洞,位于论坛奖励评论功能中。远程攻击者可以通过向 /forums.php?action=ajax_get_jf 发送携带恶意 JavaScript 代码的 c 参数,将任意 JavaScript 注入到系统中。该注入内容随后会被渲染到 /forums.php?action=viewthread 页面中的 dat

AI Predicted 6.1 Difficulty: Easy
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-38472

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A Stored XSS vulnerability in forum reward comments in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote attackers to inject arbitrary JavaScript via the c parameter in /forums.php?action=ajax_get_jf which is later rendered in the data-tooltip attribute in /forums.php?action=viewthread and interpreted as HTML by the Tooltipster configuration.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-38472

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-38472

登录查看更多情报信息。

Exploits & Public PoCs for CVE-2026-38472 (1)

Same Patch Batch · n/a · 2026-08-25 · 15 CVEs total

CVE-2026-75465 Maccms v10越权漏洞:敏感信息泄露
CVE-2026-75421 aria2<=1.37.0 IOFile::getLine函数栈缓冲区下溢漏洞
CVE-2026-52489 gpac缓冲区溢出漏洞
CVE-2026-52491 libtiff远程代码执行漏洞
CVE-2026-38467 GazellePW标签管理器存在SQL注入漏洞
CVE-2026-38468 GazellePW 任意代码执行漏洞
CVE-2026-51368 TongWeb v.7.0.24代码执行漏洞
CVE-2026-39113 SQLite < 2026-03-11 快照存在缓冲区溢出致DoS漏洞
CVE-2026-38466 GazellePW存储型XSS漏洞
CVE-2026-38465 GazellePW存储型XSS漏洞
CVE-2026-38469 GazellePW存储型XSS漏洞
CVE-2026-38474 GazellePW IP锁管理器存在越权漏洞
CVE-2026-38473 GazellePW存储型XSS漏洞
CVE-2026-38470 GazellePW API越权漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-38472

No comments yet


Leave a comment