Indicator
Type cve · source NVD CVE
Enrichment by provider
Grouped attempts with latest status; expand for attempt history.
3 attempts · first 2026-07-10T14:30:04.248672Z · last 2026-07-21T13:50:33.554553Z
Not listed in CISA KEV (local)
Types: cisa_kev
3 attempts · first 2026-07-10T14:30:04.236832Z · last 2026-07-21T13:50:33.535212Z
EPSS=0.00314
Types: epss
3 attempts · first 2026-07-10T14:30:04.253376Z · last 2026-07-21T13:50:33.560983Z
The TelSender plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting in all versions up to, and including, 1.14.14. This is due to insufficient input sanitization when processing Telegram API responses containing attacker-controlled chat titles. This makes it possible for unauthenticated attackers to inject malicious scripts via Telegram chat titles that execute when an administrator
Types: nvd_local
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
See edges, pivots, and corroboration at a glance.
Full inspector with neighbor expansion.