CVE-2026-92991
Last modified
CVE-2026-92991 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various versions due to insufficient output escaping. This makes it possible for attackers who can compromise the Sigmative API server to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page..
Description
The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various versions due to insufficient output escaping. This makes it possible for attackers who can compromise the Sigmative API server to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| bdthemes | Live Copy Paste for Elementor – Cross Domain Copy Paste & Page Duplicator | <= 1.5.6 |
| bdthemes | Pixel Gallery Addons for Elementor | <= 2.1.14 |
| bdthemes | Smart Admin Assistant | <= 2.2.0 |
| bdthemes | Ultimate Store Kit – Store Builder Addons for Elementor, WooCommerce Store Builder, EDD Store Builder | <= 3.0.7 |
| bdthemes | Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets | <= 4.2.0 |
| bdthemes | Prime Slider – Hero Slider, Carousel, WooCommerce & Post Slider Elementor Addons | <= 4.4.5 |
| bdthemes | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons | <= 8.7.14 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-92991?
How severe is CVE-2026-92991?
How do I fix CVE-2026-92991?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-92983InternLM LMDeploy through 0.17.0 in DistServe prefill/decode…7.5
- CVE-2026-92984HUBzero CMS through 2.2.32 accepts session identifiers from …8.1
- CVE-2026-92985SiYuan versions before 3.8.4 fail to escape bookmark labels …8.8
- CVE-2026-92986SiYuan before 3.8.4 renders document titles as HTML in the b…8.8
- CVE-2026-92987roxmltree through 0.21.1 performs quadratic-time attribute a…7.5
- CVE-2026-9299A flaw has been found in omec-project amf up to 2.1.1. Affec…6.3
- CVE-2026-92992A security vulnerability has been detected in Dromara mayfly…6.3
- CVE-2026-92993A vulnerability was detected in Dromara mayfly-go up to 1.11…6.3
- CVE-2026-9300A vulnerability has been found in omec-project amf up to 2.1…6.3
- CVE-2026-9301A vulnerability was found in omec-project amf up to 2.1.1. T…6.3
- CVE-2026-93013RAGFlow through 0.27.2 contains a path traversal vulnerabili…4.3
- CVE-2026-93014RosarioSIS versions before 12.9 fail to validate the filenam…7.1
Are you affected by CVE-2026-92991?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
