CVE-2026-73259 | Cesanta Mongoose up to 7.21 Directory Listing src/http.c mg_http_serve_dir/listdir cross site scripting
A vulnerability classified as problematic was found in Cesanta Mongoose up to 7.21. The affected element is the function mg_http_serve_dir/listdir of the file src/http.c of the component Directory Listing. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2026-73259. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More