THREAT OPS › Threat News › [NVD] CVE-2026-68583 (MEDIUM 5.4) — luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator views the AdBlock Fast status page, the injected payload executes in the administr
[NVD] CVE-2026-68583 (MEDIUM 5.4) — luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator views the AdBlock Fast status page, the injected payload executes in the administr
CVE-2026-68583 CVSS: 5.4 MEDIUM Published: 2026-08-02T13:16:54.377
luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator views the AdBlock Fast status page, the injected payload executes in the administrator's browser under the LuCI origin.
Indicators of compromise
- CVE-2026-68583cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-68583