CVE-2026-7089General

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in code-projects Home Service System 1.0. The impacted element is an unknown function of the file /booking.php of the component Appointment Booking. The manipulation of the argument fname/lname leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-27: 3Technical Details · 2026-04-27: 204-27
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-7089 A security vulnerability has been detected in code-projects Home Service System 1.0. The impacted element is an unknown function of the file /booking.php of the compone… https://www.cve.org/CVERecord?id=CVE-2026-7089

    Post summary

    The post indicates that CVE-2026-7089 has been detected in code-projects Home Service System 1.0 but provides no technical or remedial details.

    0001080
    57.3K followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    General

    🏠 CVE-2026-7089 — code-projects Home Service System 1.0 contains an XSS flaw in /booking.php, where the fname and lname parameters can be manipulated to inject script into appointment booking flows. Public booking forms make this kind of issue easy to reach. https://nvd.nist.gov/vuln/detail/CVE-2026-7089

    Post summary

    The post reports an XSS vulnerability (CVE‑2026‑7089) in the Home Service System’s booking form, noting that the fname and lname fields can be used for script injection, but it does not provide any PoC, exploit code, patch, or evidence of in‑the‑wild attacks.

    1000044
    1.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7089 Cross-Site Scripting in Code-Projects Home Service System 1.0 Appointment Booking https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7089

    Post summary

    The post announces the discovery of CVE-2026‑7089, a cross‑site scripting flaw in Code‑Projects Home Service System 1.0’s appointment booking feature, with no PoC, exploit code, or mitigation details shared.

    0000148
    4.0K followersView on X

Explore more