Review reviewCritical
CVE-2026-36748
the affected product
RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.
- CVSS
- 9
- EPSS
- 0.30% 22.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.04