CVE Database
/

CVE-2026-39400

Back to search

CVE-2026-39400

Published: Apr 7, 2026

Modified: Apr 15, 2026

PUBLISHED

Description

Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, a non-admin user with create_events and run_events privileges can inject arbitrary JavaScript through job output fields (html.content, html.title, table.header, table.rows, table.caption). The server stores this data without sanitization, and the client renders it via innerHTML on the Job Details page. This vulnerability is fixed in 0.9.111.

VendorProductVersions

jhuckaby

Cronicle

affected
< 0.9.111

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2026-39400 - Security Vulnerability | QwikSec