Skip to main content

BACULARIS

[ RESEARCH ] - CVE-2026-88743 - Stored XSS in Bacularis 4.7.0 - 6.5.0 - director tags
·446 words·3 mins
RESEARCH CVE-2026-88743 BACULARIS
Stored XSS affects all users via globally accessible tags. Add a global tag in JobDefs and set its value to an XSS payload. Once assigned, it executes for every user who can view jobs.
[ RESEARCH ] - CVE-2026-88742 - Stored Cross Site Scripting (XSS) in Bacularis 1.0.0 - 6.5.0 client address
·266 words·2 mins
RESEARCH CVE-2026-88742 BACULARIS
A stored XSS affects all users who can view client details. Add a client with the XSS payload in the address field, save it, then click Details to execute the payload.