CVE-2026-78178

Severity CVSS v4.0:
MEDIUM
Type:
CWE-94 Code Injection
Publication date:
24/08/2026
Last modified:
27/08/2026

Description

A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/jqxBaseFramework.extend of the file jqwidgets/jqx-all.js. This manipulation causes improperly controlled modification of object prototype attributes. The attack can be initiated remotely. The reported GitHub issue was closed with the label "not planned".