← Vulnerability feed

Vulnerability record · CVE-2026-65937 · published 12 August 2026

CVE-2026-65937: Progress whatsup gold cross-site scripting vulnerability

Progress · Whatsup Gold

In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content.

8.0 CVSS 3.1 High EPSS 0.41% · top 67.2% CWE-79 · Cross-site scriptingCWE-94 · Code injection
8.0CVSS 3.1 base score
0.41%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
2 Sep 2026Last modified by NVD

Description

In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content.

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-65937 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-6670Progress WhatsUp Gold SQL Injection Exposes Encrypted PasswordsWhatsUp Gold versions before 2024.0.0 contain a SQL injection flaw (CWE-89) that an unauthenticated attacker can use to retrieve users' encrypted pas…KEVEPSS 93%analysed9.8CVE-2024-4885Progress WhatsUp Gold path traversal enables unauthenticated remote code executionWhatsUp Gold versions before 2023.1.3 contain a path traversal flaw in WhatsUp.ExportUtilities.Export.GetFileWithoutZip that allows unauthenticated a…KEVEPSS 99%analysed9.8CVE-2024-46909WhatsUp Gold pre-2024.0.1 remote code execution flawWhatsUp Gold versions before 2024.0.1 contain a flaw that lets a remote, unauthenticated attacker execute code in the context of the service account.…EPSS 49%analysed9.8CVE-2024-6671Progress whatsup gold sql injection vulnerabilityIn WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an …EPSS 19%9.8CVE-2024-4883WhatsUp Gold NmApi.exe unauthenticated remote code executionProgress WhatsUp Gold versions released before 2023.1.3 contain a remote code execution flaw reachable through NmApi.exe. An unauthenticated attacker…EPSS 65%analysed9.8CVE-2024-4884Progress whatsup gold command injection vulnerabilityIn WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.…EPSS 24%9.8CVE-2018-8938Progress whatsup gold code injection vulnerabilityA Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can inject a specially cr…EPSS 2.3%9.8CVE-2018-8939Progress whatsup gold server-side request forgery (ssrf) vulnerabilityAn SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit specially crafted requests via the…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2026-65937), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.