Description
Improper input validation vulnerability in bizwell xClick allows Stored XSS.

This issue affects xClick: R2, R3, and R3.1.
Published: 2026-09-15
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS
Action: Apply Patch
AI Analysis

Impact

The vulnerability in bizwell xClick arises from improper validation of user input, allowing an attacker to embed malicious scripts that are stored within the application. When a victim accesses the affected page, the script executes in their browser, which can lead to theft of session cookies, authentication tokens, or other sensitive data, and may also be used for defacement or phishing. The weakness is a CWE-20 input validation flaw.

Affected Systems

The affected product is bizwell xClick. Versions R2, R3, and R3.1 are impacted. Users on these releases should verify their current version and consider applying available updates.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity. The EPSS score is less than 1%, implying a low exploitation probability at present; however, the vulnerability remains present and could still be abused by attackers who craft malicious user input that is stored by the system. The flaw is not listed in the CISA KEV catalog, so no large‑scale exploits have been reported yet. Attackers can inject scripts into user‑generated content; when other users view this content, the injected scripts execute in their browsers, potentially stealing cookies, tokens, or user data.

Generated by OpenCVE AI on September 17, 2026 at 18:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest version of bizwell xClick that contains the XSS fix, or apply vendor‑issued patch if available.
  • Sanitize all user‑supplied input and use proper output encoding (e.g., context‑aware HTML escaping) to prevent injection of executable scripts.
  • Implement a Content Security Policy that disallows inline scripts and restricts execution to trusted domains to mitigate the impact of any remaining XSS vectors.

Generated by OpenCVE AI on September 17, 2026 at 18:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Stored XSS in bizwell xClick via Improper Input Validation

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Bizwell
Bizwell xclick
Vendors & Products Bizwell
Bizwell xclick

Wed, 16 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Title Stored XSS via Improper Input Validation in bizwell xClick

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Title Stored XSS via Improper Input Validation in bizwell xClick

Tue, 15 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description Improper input validation vulnerability in bizwell xClick allows Stored XSS. This issue affects xClick: R2, R3, and R3.1.
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: FSI

Published:

Updated: 2026-09-15T17:31:45.976Z

Reserved: 2026-09-10T00:46:51.887Z

Link: CVE-2026-88261

cve-icon Vulnrichment

Updated: 2026-09-15T17:26:33.247Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T03:17:06.083

Modified: 2026-09-18T19:41:42.593

Link: CVE-2026-88261

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-20

    Improper Input Validation