CVE-2026-11372
published 2026-06-22CVE-2026-11372: IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary…
PriorityP426medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.17%
6.1th percentile
IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | 5.0.2 – 5.0.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting.
ghsa_unreviewed·2026-06-22
CVE-2026-11372 [MEDIUM] CWE-79 IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting.
IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
VulDB
IBM TRIRIGA Application Platform up to 5.0.3 cross site scripting
vuldb·2026-06-22·CVSS 5.4
CVE-2026-11372 [MEDIUM] IBM TRIRIGA Application Platform up to 5.0.3 cross site scripting
A vulnerability was found in IBM TRIRIGA Application Platform up to 5.0.3. It has been rated as problematic. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2026-11372. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-22
Published