CVE-2026-88742

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Bacularis 1.0.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in the client address field.

Published 2026-09-15. Last modified 2026-09-22.