Home

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimePictra allows Query System for Information.This issue affects TimePictra: from 11.0 through 11.3 SP2.

PUBLISHED Reserved 2026-02-23 | Published 2026-02-28 | Updated 2026-02-28 | Assigner Microchip




CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Product status

Default status
unaffected

11.0 (custom)
affected

Timeline

2026-02-04:Reported

Credits

Steve Lin reporter

Bastion Security reporter

References

www.microchip.com/.../timepictra-stored-cross-site-scripting vendor-advisory

cve.org (CVE-2026-3010)

nvd.nist.gov (CVE-2026-3010)

Download JSON