PT-2026-34014 · Websystems · Webtotum 2026

Acme

+1

·

Published

2026-04-21

·

Updated

2026-04-21

·

CVE-2026-6743

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions WebSystems WebTOTUM 2026
Description A flaw in the Calendar component allows for remote cross site scripting, which occurs when a malicious script is injected into a trusted website and executed in the victim's browser.
Recommendations Upgrade the Calendar component to the fixed version.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6743

Affected Products

Webtotum 2026