Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 16 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-office users who follow a crafted link can execute injected JavaScript in their administrative session via the child_features parameter. | |
| Title | QloApps through 1.7.0 Reflected XSS via Hotel Feature Validation Errors | |
| First Time appeared |
Webkul
Webkul qloapps |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Webkul
Webkul qloapps |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T18:02:11.766Z
Reserved: 2026-09-15T19:27:24.634Z
Link: CVE-2026-92234
Updated: 2026-09-16T18:01:23.233Z
Status : Deferred
Published: 2026-09-15T21:16:49.350
Modified: 2026-09-16T20:21:01.047
Link: CVE-2026-92234
No data.
OpenCVE Enrichment
Updated: 2026-09-16T21:00:08Z