CVE-2026-85127
VikBooking 1.8.8 - 1.8.14 - Unauthenticated Stored XSS via SVG Chat Attachment
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is executed in the context of an administrator viewing the conversation.
| Vendor | unknown |
| Product | vikbooking hotel booking engine & pms |
| Published | Sep 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown vikbooking hotel booking engine & pms
Be the first to know when new unknown vulnerabilities affecting unknown vikbooking hotel booking engine & pms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / VikBooking Hotel Booking Engine & PMS
1.8.8 < 1.8.15
References
Credits
anhdung1329 WPScan