All 3 CVE vulnerabilities found in Optima Express IDX, with AI-generated Chinese analysis, references, and POCs.
Vendor: ihomefinder
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-96899 | Optima Express 8.6.0 - 8.7.5 - Author+ Stored XSS via faq_script | - | - | 2026-09-27 |
| CVE-2026-96897 | Optima Express 8.5.0 - 8.7.5 - Unauthenticated Author Account Creation & Application Password Rotation via ihf_clear_cache | - | - | 2026-09-27 |
| CVE-2026-93901 | Optima Express IDX <= 8.7.5 - Unauthenticated Privilege Escalation to 'ihf_clear_cache' AJAX Action to Author Role Assignment CWE-269 | 7.3 | High | 2026-09-25 |
All 3 known CVE vulnerabilities affecting Optima Express IDX with full Chinese analysis, references, and POCs where available.