CVE-2026-103589

CVE-2026-103589 published: QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values in input attributes. Attackers can induce authenticated back-office users to sub...

View full NVD advisory → ← Back to CVE watch