CVE-2026-11903
EUVD-2026-4228008.07.2026, 15:16
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module).
This issue affects MOVEit Transfer: from 2026.0.0 before 2026.0.1, from 2025.1.0 before 2025.1.4, from 2025.0.0 before 2025.0.8.Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| progress | moveit_transfer | 𝑥 ≤ 2024.1.8 |
| progress | moveit_transfer | 2025.0.0 ≤ 𝑥 < 2025.0.8 |
| progress | moveit_transfer | 2025.1.0 ≤ 𝑥 < 2025.1.4 |
| progress | moveit_transfer | 2026.0.0 |
𝑥
= Vulnerable software versions