CVE-2026-92234
Medium · CVSS 5.1Published 2026-09-15
CVSS
5.1
Medium
EPSS
—
exploit probability
Active Exploit
No
not yet listed
What is CVE-2026-92234?
QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-office users who follow a crafted link can execute injected JavaScript in their administrative session via the child_features parameter.
CVSS Score Explained
CVSS 5.1 is Medium severity. Exploitation usually requires some specific conditions (local access, user interaction, or a particular config). Still worth patching in your next maintenance window.
EPSS Exploitation Probability
No EPSS score yet — model needs more data on this CVE.
References & Patches
- ›https://github.com/Qloapps/QloApps
- ›https://github.com/Qloapps/QloApps/blob/v1.7.0/modules/hotelreservationsystem/controllers/admin/AdminHotelfeaturesController.php
- ›https://github.com/Qloapps/QloApps/commit/54a3b30e4e5c2d6b224dc8fe55e75db173064b91
- ›https://github.com/Qloapps/QloApps/pull/1796
- ›https://hackmd.io/@leediay/r1aoFrMFGl
- ›https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-hotel-feature-validation-errors
Track vulnerabilities for your stack
Tell us what tech you run — Node.js, Python, Java, nginx, whatever — and get a weekly email when new CVEs affect it.
Recent CVEs
- CVE-2026-85893Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.8.8
- CVE-2026-69486Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.8.8
- CVE-2025-11395A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host machine with the privileges of the user running Podman.5.5
- CVE-2026-92248A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This leads to an undersized heap allocation, resulting in a heap-based buffer overflow when the image data is decoded. This buffer overflow corrupts adjacent heap objects, allowing for a controlled memory write that can result in an application crash or arbitrary code execution.7.8
- CVE-2026-92255Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by improper use of a string handling API. Attackers can trigger an unterminated buffer over-read by exploiting this flaw in the affected component, potentially exposing adjacent memory contents.5.3
- CVE-2026-92256NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l2tpd_config_show_cgi.c, ipsec_show_cgi.c, and mod_vpn_remote/plan.json read handlers. Attackers can query l2tpd_config_show.cgi to expose stored IPsec PSK and RSA key material.7.1