CVE-2026-71189
Toptech TMS7 and TopHAT Cross-site Scripting
CVSS Score
3.5
EPSS Score
0.0%
EPSS Percentile
0th
An attacker can construct a request that, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application.
| CWE | CWE-79 |
| Vendor | toptech systems |
| Product | tms7 |
| Published | Sep 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for toptech systems tms7
Be the first to know when new low vulnerabilities affecting toptech systems tms7 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
Toptech Systems / TMS7
7.6.3
Toptech Systems / TopHAT
7.6.3
References
Credits
Sachin Shetty and Roy Duisters of Shell CyberDefence reported this vulnerability to Toptech and CISA.