Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-1769-WriteUp — Public write-up and disclosure timeline for CVE-2026-1769 (Stored XSS in Xerox CentreWare Web) | Kitploit
Tools/GitHubGitHub/leox48/cve-2026-1769-writeup
Vulnerability AnalysisWeb SecurityPapers & ResearchLearning & EducationCurated Resources
GitHubleox48/cve-2026-1769-writeup

CVE-2026-1769-WriteUp

Public write-up and disclosure timeline for CVE-2026-1769 (Stored XSS in Xerox CentreWare Web)

View Repository
112h 27m agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-1769 — Stored XSS in Xerox CentreWare Web

Disclosure timeline and technical write-up for CVE-2026-1769, a Stored Cross-Site Scripting vulnerability I identified and responsibly disclosed to Xerox.

  • CVE record: cve.org/CVERecord?id=CVE-2026-1769
  • Vendor security bulletin: XRX26-003
  • CWE: CWE-79 — Improper Neutralization of Input During Web Page Generation
  • CVSS 3.1: 5.3 (Medium) — AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
  • Affected software: Xerox CentreWare Web, up to and including v7.0.6
  • Fixed in: v7.2.2.25

Disclosure Timeline

DateEvent
Jul 2025Vulnerability discovered and reported to Xerox
Oct 2025Vendor acknowledged the report
Jan 2026Vendor released a fix
Jan 2026Fix confirmed
Feb 2026CVE-2026-1769 publicly assigned and published

Contents

  • WRITEUP.md — technical write-up: vulnerability class, root cause, impact, and remediation guidance

Scope of This Repository

This repository documents the vulnerability at the level already made public by the official CVE record and the vendor's own security bulletin. It does not include exploit code, internal assessment materials, or details beyond what the vendor has already disclosed.

Download Tool