CVE-2026-5738
Reflected XSS in BilPark's DoXBASE
CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in BilPark Informatics Technologies Industry and Trade Inc. DoXBASE allows Cross Zone Scripting. This issue affects DoXBASE: through 27082026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
| CWE | CWE-79 |
| Vendor | bilpark informatics technologies industry and trade inc. |
| Product | doxbase |
| Published | Aug 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for bilpark informatics technologies industry and trade inc. doxbase
Be the first to know when new medium vulnerabilities affecting bilpark informatics technologies industry and trade inc. doxbase are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
BilPark Informatics Technologies Industry and Trade Inc. / DoXBASE
0 ≤ 27082026
References
Credits
Akıner KISA