CVE-2026-28338 | PMD up to 7.21.x String cross site scripting (EUVD-2026-9069)
A vulnerability was found in PMD up to 7.21.x and classified as problematic. The impacted element is an unknown function of the component String Handler. Such manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-28338. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.