{"id":"CVE-2026-34951","summary":"Reflected XSS in footer.php in Workbench Allows Attackers to Hijack Authenticated Sessions","details":"Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. Prior to 65.0.0, Workbench contains a reflected cross-site scripting vulnerability via the footerScripts parameter, which does not sanitize user-supplied input before rendering it in the page response. Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Workbench allows XSS Targeting Error Pages. This vulnerability is fixed in 65.0.0.","aliases":["GHSA-j94x-h584-rjf9"],"modified":"2026-08-12T03:51:45.307469128Z","published":"2026-04-06T15:58:45.583Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34951.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34951.json"},{"type":"ADVISORY","url":"https://github.com/forceworkbench/forceworkbench/security/advisories/GHSA-j94x-h584-rjf9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34951"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/forceworkbench/forceworkbench","events":[{"introduced":"0"},{"fixed":"2f2820a6f76fdd1dac31bf1c167692ae4c159bb5"}],"database_specific":{"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:salesforce:workbench:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"65.0.0"}]}}],"versions":["53.0.0","52.0.0","51.0.0","50.0.0","49.0.0","48.0.0","47.0.0","46.0.0","45.0.1","45.0.0","43.0.0","42.0.0","41.0.1","41.0.0","40.0.0","39.0.0","37.0.2","37.0.1","37.0.0","36.0.7","36.0.6","36.0.5","36.0.4","36.0.3","36.0.2","36.0.1","36.0.0","35.0.0","34.0.13","34.0.12","34.0.9","34.0.8","34.0.7","34.0.6","34.0.5","34.0.4","34.0.3","34.0.2","34.0.1","34.0.0","29.0.9","29.0.8","29.0.7","29.0.6","29.0.5","29.0.4","29.0.4-Beta-5","29.0.4-Beta-6","29.0.4-Beta-4","29.0.4-Beta-3","29.0.4-Beta-2","29.0.4-Beta-1","29.0.3","29.0.2","29.0.1","29.0.0","28.0.2","28.0.1","28.0.0","27.0.9","27.0.8","27.0.7","27.0.6","27.0.5","27.0.4","27.0.3","27.0.2","27.0.1","27.0.0","26.0.1","26.0.0","25.0.2","25.0.1","25.0.0","25.0.0-Beta-1","24.0.0","23.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34951.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}