CVE-2026-6486 is a cross-site scripting (XSS) vulnerability in Classroom Bookings up to version 2.17.0, affecting the User Display Name Handler function within the layout.php file. The vulnerability exists in the displayname parameter and allows remote attackers to inject malicious scripts through user display names. The vendor has released a patch in version 2.17.1 (commit 69c3c9bb8a17f1ea572d8f4502bf238f0214c98a) and responded professionally to early disclosure. The vulnerability carries a CVSS 3.5 LOW severity rating with network-based attack vector and low attack complexity, though it requires user interaction and valid credentials. The impact is limited to integrity violations with no confidentiality or availability impact. The EPSS score of 0.00033 indicates minimal exploitation probability in the wild compared to other CVEs. Exploitation status shows the vulnerability is currently on the active Hot List with public exploit availability, though the extremely low EPSS score suggests minimal real-world exploitation activity. There is no indication of active widespread exploitation or inclusion in known exploitation databases at this time. Immediate patching to version 2.17.1 is recommended, particularly for systems with internet-facing deployment or handling sensitive classroom data.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | Classroombookings | 2.0, 2.1, 2.10, 2.11, 2.12, 2.13, 2.14, 2.15, 2.16, 2.17.0, 2.2, 2.3, 2.4, 2.5, 2.6, 2.7, 2.8, 2.9CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.