Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code via the item.php, field-select.js and tags.js components
https://github.com/Securify-AI/CVE-2026-39275
https://github.com/Cockpit-HQ/Cockpit/commit/d70dc5059732fc97bd65aa3583cd0f88631a3c78