Junglewise Threat Intelligence

CVE-2026-88261: Bizwell xClick stored XSS via improper input validation

CVE-2026-88261 · Severity: info · Published 2026-09-15

Executive brief

Bizwell xClick is a groupware platform used for enterprise collaboration, including email, approvals, scheduling, and document management. A stored cross-site scripting (XSS) vulnerability in xClick allows an attacker to inject malicious scripts that persist in the application, potentially compromising user sessions, stealing credentials, or defacing content visible to other users.

Technical details

This vulnerability is a stored cross-site scripting (XSS) flaw caused by improper input validation in Bizwell xClick, a web-based groupware platform. An attacker can inject malicious JavaScript code through unvalidated input fields, which persists in the application's database and is executed in the browsers of other users when they view the affected content. The attack vector is network-based; no special authentication or privileges are necessarily required depending on where the input validation failure occurs. Successful exploitation allows an attacker to steal session cookies, harvest credentials, redirect users to phishing sites, or perform actions on behalf of victims. Patches are not mentioned in the advisory; users of R2, R3, and R3.1 should contact Bizwell for remediation guidance.

Affected products

  • Bizwell xClick R2, R3, R3.1

Timeline

  • 2026-09-15: disclosed

References

Related threats