Cross-site scripting in Database Performance Analyzer - CVE-2026-28322
Published: July 27, 2026
Database Performance Analyzer
Detailed vulnerability description
The vulnerability allows a remote privileged user to execute arbitrary script code in a user's browser.
The vulnerability exists due to cross-site scripting in the web interface when processing stored user-supplied content. A remote privileged user can inject a specially crafted script payload to execute arbitrary script code in a user's browser.
User interaction is required for the crafted content to be viewed.