Junglewise Threat Intelligence

CVE-2026-3251: Webremium Istanbul Web Design Mezunum Satiyorum stored XSS

CVE-2026-3251 · Severity: medium · CVSS 6.4 · Published 2026-07-10

Executive brief

Webremium Istanbul Web Design's Mezunum Satiyorum software contains a security flaw that allows attackers to inject malicious scripts into the platform. This software is used for web design and e-commerce management. If exploited, an attacker could steal user session information, redirect visitors to malicious websites, or deface the site's content, potentially damaging the organization's reputation and compromising customer data.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Webremium Istanbul Web Design Mezunum Satiyorum versions 1.2.504 through 10072026. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An authenticated attacker with low privileges can inject malicious scripts into the application's database, which are then executed in the browser of any user viewing the affected page. This can lead to session hijacking or unauthorized actions in the context of the victim's browser. As of the disclosure date, the vendor has not responded to reports of this vulnerability.

Affected products

  • Webremium Istanbul Web Design Mezunum Satiyorum 1.2.504 through 10072026

Timeline

  • 2026-07-10: advisory: NVD and TR-CERT published the vulnerability details.
  • 2026-07-10: disclosed: Public disclosure occurred after the vendor failed to respond to early contact.

References