CVE-2026-7089 - Vulnerability Analysis
MediumCVSS: 4.3Last Updated: April 29, 2026
code-projects Home Service System - Stored XSS
Published: April 27, 2026Updated: April 29, 2026PoC AvailableRemote Exploitable
Overview
code-projects Home Service System 1.0 contains a stored XSS caused by manipulation of "fname" and "lname" arguments in /booking.php Appointment Booking component, letting remote attackers execute scripts, exploit requires crafted input.
Severity & Score
Severity: Medium
CVSS Score: 4.3
Impact
Remote attackers can execute arbitrary scripts in users' browsers, potentially stealing data or performing actions on their behalf.
Mitigation
Update to the latest version.
References
Related Resources
Details
- CVE ID
- CVE-2026-7089
- Severity
- Medium
- CVSS Score
- 4.3
- Type
- stored_xss
- Status
- rejected
CWE
- CWE-79
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N