Junglewise Threat Intelligence

CVE-2026-19057: Gastromenum Ticket and QR Menu System stored XSS

CVE-2026-19057 · Severity: medium · CVSS 5.4 · Published 2026-09-04

Executive brief

Gastromenum Ticket and QR Menu System is a web-based platform for restaurant menu management and QR code ticketing. A stored cross-site scripting (XSS) vulnerability allows authenticated or unauthenticated attackers to inject malicious scripts that execute in other users' browsers, potentially compromising account sessions or stealing sensitive data.

Technical details

The vulnerability is an improper neutralization of user input during web page generation, resulting in a stored XSS flaw. Attack input is stored server-side and executed in victims' browsers when they access affected pages. The flaw affects Gastromenum Ticket and QR Menu System versions prior to 2026.08.31. A successful exploit allows an attacker to execute arbitrary JavaScript in the context of a user's session, potentially leading to session hijacking, credential theft, or malware distribution. Patches are available in version 2026.08.31 and later.

Affected products

  • Gastromenum Ticket and QR Menu System before 2026.08.31

Timeline

  • 2026-09-04: disclosed

References

Related threats