CVE-2026-5705Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown functionality of the file /booknow.php of the component Booking Endpoint. Such manipulation of the argument roomname leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-07); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-04-07: 2Mentions · 2026-04-20: 2Technical Details · 2026-04-07: 104-0704-20
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-072
Disclosure2
2026-04-202
General2
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-5705 A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown functionality of the file /booknow.php of the com… https://www.cve.org/CVERecord?id=CVE-2026-5705 ----- Traducción: CVE-2026-5705 Se … http://infoflow.cloud`

    Post summary

    The provided text merely cites CVE-2026-5705 and a link to its record, offering no PoC, exploit details, patch information, or technical specifics about the vulnerability.

    0000031
    72 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5705 A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown functionality of the file /booknow.php of the com… https://www.cve.org/CVERecord?id=CVE-2026-5705

    Post summary

    The text merely states that CVE‑2026‑5705 is an unknown functionality vulnerability in /booknow.php of Online Hotel Booking 1.0, with no additional details or actionable information.

    00000232
    57.2K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-5705 📊 Severity: 4.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5705 #CVE-2026-5705 #CVE #Medium #CyberSecurity #InfoSec https://t.co/EnMLgA93zQ

    Post summary

    The tweet announces the existence of CVE-2026-5705 with a medium severity rating and unspecified affected products, providing no additional technical or mitigation details.

    0000030
    123 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5705 Cross Site Scripting in Code-Projects Online Hotel Booking 1.0 Booking Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5705

    Post summary

    A Cross Site Scripting vulnerability (CVE‑2026‑5705) has been identified in the booking endpoint of Code‑Projects Online Hotel Booking 1.0, with details available at the provided URL.

    0000049
    4.0K followersView on X

Explore more