SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-88261

MEDIUM · CVSS 5.1 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability in bizwell xClick, specifically in versions R2, R3, and R3.1, arises from improper input validation, enabling Stored Cross-Site Scripting (XSS) attacks. This flaw could allow an attacker to inject malicious scripts that execute in the context of users' browsers, potentially compromising sensitive data or session integrity. Organizations utilizing these versions of xClick should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-88261
Severity
MEDIUM
CVSS
5.1
EPSS
0.22%

Original NVD Description

Improper input validation vulnerability in bizwell xClick allows Stored XSS. This issue affects xClick: R2, R3, and R3.1.