Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6486

16
FAUCET Score

CVE-2026-6486 is a cross-site scripting (XSS) vulnerability in Classroom Bookings up to version 2.17.0, affecting the User Display Name Handler function within the layout.php file. The vulnerability exists in the displayname parameter and allows remote attackers to inject malicious scripts through user display names. The vendor has released a patch in version 2.17.1 (commit 69c3c9bb8a17f1ea572d8f4502bf238f0214c98a) and responded professionally to early disclosure. The vulnerability carries a CVSS 3.5 LOW severity rating with network-based attack vector and low attack complexity, though it requires user interaction and valid credentials. The impact is limited to integrity violations with no confidentiality or availability impact. The EPSS score of 0.00033 indicates minimal exploitation probability in the wild compared to other CVEs. Exploitation status shows the vulnerability is currently on the active Hot List with public exploit availability, though the extremely low EPSS score suggests minimal real-world exploitation activity. There is no indication of active widespread exploitation or inclusion in known exploitation databases at this time. Immediate patching to version 2.17.1 is recommended, particularly for systems with internet-facing deployment or handling sensitive classroom data.

Impacted Technologies

VendorProductVersion(s)CPE
N/AClassroombookings
2.0, 2.1, 2.10, 2.11, 2.12, 2.13, 2.14, 2.15, 2.16, 2.17.0, 2.2, 2.3, 2.4, 2.5, 2.6, 2.7, 2.8, 2.9CNA affected

CVSS Data

CVSS version used by this source: 4.0

2.0LOW

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
PASSIVE
VS Confidentiality
NONE
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
11.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0021 is in the 25th percentile among its peer group of 406 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / classroombookings/classroombookings
github.com / classroombookings/classroombookings/commit/69c3c9bb8a17f1ea572d8f4502bf238f0214c98a
github.com / classroombookings/classroombookings/pull/83
github.com / classroombookings/classroombookings/releases/tag/v2.17.1
github.com / sudo-secure/security-research/blob/main/classroombookings/stored-xss/PoC.md
vuldb.com / submit/786154
vuldb.com / vuln/358027
vuldb.com / vuln/358027/cti