Home

Description

HTML injection vulnerability in multiple Botble products such as TransP, Athena, Martfury, and Homzen, consisting of an HTML injection due to a lack of proper validation of user input by sending a request to '/search' using the 'q' parameter.

PUBLISHED Reserved 2026-01-19 | Published 2026-01-20 | Updated 2026-01-20 | Assigner INCIBE




MEDIUM: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Product status

Default status
unaffected

all versions
affected

Default status
unaffected

all versions
affected

Default status
unaffected

all versions
affected

Default status
unaffected

all versions
affected

Credits

Gonzalo Aguilar García (6h4ack) finder

References

www.incibe.es/...iso/html-injection-multiple-botble-products

cve.org (CVE-2026-1183)

nvd.nist.gov (CVE-2026-1183)

Download JSON