AllCyberNews

CVE-2026-71189

Toptech TMS7 and TopHAT Cross-site Scripting

CVSS 4.8 medium · Toptech Systems TMS7 · published 2026-09-29

An attacker can construct a request that, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application.

Coverage 1 source

  1. 2026-09-29 CISA Cybersecurity Advisories high Toptech TMS7 and TopHAT

    Multiple vulnerabilities affect Toptech TMS7 and TopHAT versions 7.6.3.

Mentioned with

CVE-2026-63713 CVE-2026-68068 CVE-2026-68954 CVE-2026-69662 CVE-2026-70356 CVE-2026-71302 CVE-2026-71379 CVE-2026-72507 CVE-2026-72510

Also covered