CVE-2026-103587

CVE-2026-103587 published: QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into template variables without validation. Attackers can craft a...

View full NVD advisory → ← Back to CVE watch