Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6743

17
FAUCET Score

CVE-2026-6743 is a cross-site scripting (XSS) vulnerability in the Calendar component of WebSystems WebTOTUM 2026. The vulnerability affects an undetermined function within this component and allows remote attackers to inject malicious scripts. The vulnerability carries a CVSS score of 3.5 (LOW severity) with a network-based attack vector requiring low complexity and user interaction. The attack requires valid login credentials and user action to execute, resulting in limited impact to integrity with no confidentiality or availability compromise. The FAUCET Risk Score of 36.0 indicates below-average risk in the broader threat landscape. The vulnerability has been publicly disclosed and proof-of-concept code is available, placing it on the Hot List for active monitoring. However, it is not currently listed on CISA's Known Exploited Vulnerabilities catalog. The vendor responded promptly with professional remediation, releasing a patched version. Organizations should prioritize upgrading to the fixed version to eliminate this exposure, though the low severity and requirement for authentication limit immediate tactical risk.

Impacted Technologies

VendorProductVersion(s)CPE
WebSystemsWebTOTUM
2026CNA affected

CVSS Data

CVSS version used by this source: 4.0

2.0LOW

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
PASSIVE
VS Confidentiality
NONE
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.19%
Probability of exploitation in next 30 days
EPSS Percentile
9.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0019 is in the 13th percentile among its peer group of 406 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

olografix.org / acme/WebTOTUM-POC.gif
vuldb.com / submit/794617
vuldb.com / vuln/358434
vuldb.com / vuln/358434/cti
websys.eu / gestionale-online-in-cloud-per-pmi-callcenter