Impact
An improper neutralization of input during web page generation in Webbeyaz Web Design's Mediküm Web permits stored cross‑site scripting. An attacker who can provide data that is persisted and subsequently rendered in a browser may execute arbitrary JavaScript in the context of the affected site, potentially hijacking user sessions, defacing content, or delivering malicious payloads to visitors. The CWE classification is 79, indicating a lack of input validation or output escaping.
Affected Systems
The vulnerability impacts Webbeyaz Web Design's Mediküm Web up through the release dated 08‑07‑2026. No specific version numbers are listed, and the vendor has indicated the product is no longer supported.
Risk and Exploitability
The CVSS base score is 5.4, reflecting a moderate severity. The EPSS score is <1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no evidence of widespread exploitation yet. The attack vector is inferred to be an input field that stores user‑supplied data; the attacker must supply malicious content that is later rendered in the web page. No special privileges appear to be required beyond access to the input mechanism, and the impact is limited to the affected web application.
OpenCVE Enrichment