Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Stored XSS.

This issue affects Mediküm Web: through 08072026. NOTE: The vendor was contacted and it was learned that the product is not supported.
Published: 2026-07-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper neutralization of input during web page generation in Web­beyaz Web Design's Mediküm Web permits stored cross‑site scripting. An attacker who can provide data that is persisted and subsequently rendered in a browser may execute arbitrary JavaScript in the context of the affected site, potentially hijacking user sessions, defacing content, or delivering malicious payloads to visitors. The CWE classification is 79, indicating a lack of input validation or output escaping.

Affected Systems

The vulnerability impacts Web­beyaz Web Design's Mediküm Web up through the release dated 08‑07‑2026. No specific version numbers are listed, and the vendor has indicated the product is no longer supported.

Risk and Exploitability

The CVSS base score is 5.4, reflecting a moderate severity. The EPSS score is <1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no evidence of widespread exploitation yet. The attack vector is inferred to be an input field that stores user‑supplied data; the attacker must supply malicious content that is later rendered in the web page. No special privileges appear to be required beyond access to the input mechanism, and the impact is limited to the affected web application.

Generated by OpenCVE AI on July 28, 2026 at 09:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable or remove Mediküm Web from all active production environments.
  • Implement server‑side input sanitization or a whitelist for any remaining legacy forms that continue to accept user data.
  • Configure a web application firewall to block malicious input.
  • Restrict access to the vulnerable pages to trusted personnel only.
  • Monitor for anomalous activity.

Generated by OpenCVE AI on July 28, 2026 at 09:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Webbeyaz Website Design
Webbeyaz Website Design mediküm Web
Vendors & Products Webbeyaz Website Design
Webbeyaz Website Design mediküm Web

Wed, 08 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Stored XSS. This issue affects Mediküm Web: through 08072026. NOTE: The vendor was contacted and it was learned that the product is not supported.
Title Stored XSS in Webbeyaz's Mediküm Web
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Webbeyaz Website Design Mediküm Web
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-09T08:55:25.835Z

Reserved: 2026-05-11T12:45:55.574Z

Link: CVE-2026-8315

cve-icon Vulnrichment

Updated: 2026-07-08T14:45:40.549Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:30:19Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')