4.9
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Description
Cross Site Scripting vulnerability in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code
Basic Information
ID
CVE-2026-31050
Source
mitre
Published
Apr 24, 2026 at 00:00
Modified
Apr 24, 2026 at 15:22
Affected Product
Vendor
n/a
Product
n/a
Version
n/a
Affected Versions
n/a n/a n/a
CWE Classification
References
- hostbillapp.com /changelog
- hostbillapp.com /release-notes/11-27-2025.html
- blog.hostbillapp.com /2025/12/03/hostbill-security-advisory/
- hostbillapp.com /responsible-disclosure
- hostbillapp.com /release-notes/12-01-2025.html
- github.com /Muhammad5235/HostBill-CVEs-2025/blob/main/Stored%20Cross-Site%20Scripting%20%28XSS%29%20Vulnerability/admin%20and%20client%20interfaces