CVE-2026-71189
Toptech TMS7 and TopHAT Cross-site Scripting
An attacker can construct a request that, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application.
Coverage 1 source
-
2026-09-29
CISA Cybersecurity Advisories
high
Toptech TMS7 and TopHAT
Multiple vulnerabilities affect Toptech TMS7 and TopHAT versions 7.6.3.
Mentioned with
CVE-2026-63713 CVE-2026-68068 CVE-2026-68954 CVE-2026-69662 CVE-2026-70356 CVE-2026-71302 CVE-2026-71379 CVE-2026-72507 CVE-2026-72510
Also covered
- CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands
- CVE-2026-91191 Lantronix G520 Series Cellular Gateway Improper Verification of Cryptographic Signature
- CVE-2026-86950 Apple iOS and iPadOS
- CVE-2026-84409 Lantronix G520 Series Cellular Gateway Cross-site Scripting
- CVE-2026-72510 Toptech TMS7 and TopHAT SQL Injection