AV AC PR UI S C I A CVSS EPSS %ile KEV N L L R C L L N 5.4 .0016 4.5 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Sep 10 Reserved by mitre Sep 25 Published (CNA: mitre) Sep 29 RESCORED — CVE-2026-88420. CVSS 6.1 → 5.4 (NVD).
Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L R C L L N 5.4 .0016 4.5 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Sep 10 Reserved by mitre Sep 25 Published (CNA: mitre) Sep 29 RESCORED — CVE-2026-88420. CVSS 6.1 → 5.4 (NVD).
A reflected cross-site scripting (XSS) vulnerability in the EntryAbstract.save() component of APSL puput v1.2.1 through v2.2.0 allows authenticated attackers with Wagtail Editor privileges to execute arbitrary code in the context of the victim's browser via a crafted payload.
| Date | Event | Detail |
|---|---|---|
| September 10, 2026 | Reserved | Reserved by mitre |
| September 25, 2026 | Published | Published (CNA: mitre) |
| September 29, 2026 | RESCORED | RESCORED — CVE-2026-88420. CVSS 6.1 → 5.4 (NVD). |
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
|---|---|---|---|---|
| n/a | n/a | — | n/a | — |
Authoritative record: CVE-2026-88420 at cve.org
Weaknesses: CWE-79
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-88420 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.