SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityReceived

CVE-2026-51133

Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary code via the size parameter in ptzpreset.pml component and the showmovies.pml component

EXPLOITMEDIUM 6.1EPSS 0.87%

Does this matter?

A public exploit is published in Exploit-DB, so the technical barrier is gone even though the severity is medium and EPSS is 0.9%. Treat it as high on anything reachable from the internet.

Description

Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary code via the size parameter in ptzpreset.pml component and the showmovies.pml component

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.87% probability · 57th percentile
Public exploits
1 in Exploit-DB · first 31 August 2026
CISA KEV
Not listed
Weakness
CWE-79
Source
cve@mitre.org
EPSS trend
0%3%5%19 September 2026: 0.87%19 September 202619 September 2026

EPSS 0.9% since 19 September 2026; no change recorded yet. Points are recorded when the score first appears and whenever it moves by a percentage point or more.

Public exploits (1)

Entries in Exploit-DB that cite this CVE. Links go to the Exploit-DB page and to the file in the public repository; nothing is hosted here. A verified tick means the Exploit-DB team confirmed the exploit works against the stated version.

EDB-IDTitleTypePublishedVerified
EDB-52665source ↗C-MOR 6.0104 - Cross-Site Scripting (XSS)hardware · Samir Shamdinwebapps31 August 2026no

Source: NVD record, EPSS from FIRST.org, KEV from CISA, exploits from Exploit-DB. Refreshed daily. Download this record as JSON.