Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh Addons for Elementor addons-for-elementor allows Stored XSS.This issue affects Livemesh Addons for Elementor: from n/a through <= 9.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains two Python exploit scripts, one for single-target exploitation and one for batch scanning/exploitation, plus a small target list file and a README. The code targets a Vite development server vulnerability labeled CVE-2026-39363. The exploitation flow is consistent across both scripts: request /@vite/client over HTTPS, parse the returned JavaScript to extract a wsToken, establish a WSS connection to the Vite HMR endpoint using the token and subprotocol vite-hmr, then send a crafted JSON message with event vite:invoke and name fetchModule to request file:///etc/passwd?raw from the remote host. Returned WebSocket messages are collected and written to local files. The single-target script prompts for a hostname, assumes port 5173, and is heavily instrumented for debugging: it prints request/response headers, saves all messages, filters out the default connected message, and records status. The batch script reads host:port pairs from 1.txt, iterates through targets, stores per-target output under ws_results/, and classifies successful responses by searching for the keyword 'root', indicating likely disclosure of /etc/passwd contents. Both scripts are designed to run through a local Burp Suite proxy at 127.0.0.1:8080 and explicitly disable TLS certificate validation to accommodate interception. Overall purpose: operational proof-of-concept exploit for arbitrary local file read against exposed Vite dev servers via the HMR WebSocket interface. It is not merely a detector because it actively sends an exploitation payload and attempts to retrieve sensitive file contents.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.