Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webremium Istanbul Web Design Mezunum Satiyorum allows Stored XSS.

This issue affects Mezunum Satiyorum: from 1.2.504 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-07-10
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of input. Malicious content stored in the application can be rendered in every browser that accesses the affected page, allowing an attacker to execute arbitrary client‑side scripts. This can lead to or other client‑side compromises as defined by CWE‑79.

Affected Systems

Webremium Istanbul Web Design’s Mezunum Satiyorum, versions 1.2.504 through 10072026, are affected. No other vendors or products are listed as impacted. The vendor did not respond to early disclosure, leaving the issue unresolved at this time.

Risk and Exploitability

The CVSS base score of 6.4 classifies the risk as moderate. The EPSS score of less than 1% indicates a low probability of exploitation, and the issue is not listed in the CISA KEV catalog. The most likely attack vector is that an attacker posts malicious content via the application, then persuades a legitimate user to view the stored data, at which point the injected script runs. Because vulnerability may remain exploitable for an extended period.

Generated by OpenCVE AI on July 29, 2026 at 10:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch or update to a patched version when it becomes available.
  • Sanitize all user‑generated content using OWASP‑recommended filtering or escaping.
  • Restrict content submission to trusted users and implement rules to block or filter suspicious script payloads.

Generated by OpenCVE AI on July 29, 2026 at 10:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Webremium Istanbul Web Design
Webremium Istanbul Web Design mezunum Satiyorum
Vendors & Products Webremium Istanbul Web Design
Webremium Istanbul Web Design mezunum Satiyorum

Fri, 10 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webremium Istanbul Web Design Mezunum Satiyorum allows Stored XSS. This issue affects Mezunum Satiyorum: from 1.2.504 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Title XSS in Webremium's Mezunum Satiyorum
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Webremium Istanbul Web Design Mezunum Satiyorum
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-10T17:41:50.418Z

Reserved: 2026-02-26T08:10:20.666Z

Link: CVE-2026-3251

cve-icon Vulnrichment

Updated: 2026-07-10T17:41:44.381Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T10:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')