Stored Cross-Site Scripting (XSS) vulnerability in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/configuracion/agenda/modelo-formulario-evento'. A user with permission to create personalized accounts could exploit this vulnerability simply by creating a malicious survey that would harm the entire veterinary team. At the same time, a user with low privileges could exploit this vulnerability to access unauthorized data and perform actions with elevated privileges.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Wakyma has fixed the vulnerability in the continuous integration deployed in production since February 19, 2026.
Workaround
No workaround given by the vendor.
References
History
Mon, 16 Mar 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stored Cross-Site Scripting (XSS) vulnerability in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/configuracion/agenda/modelo-formulario-evento'. A user with permission to create personalized accounts could exploit this vulnerability simply by creating a malicious survey that would harm the entire veterinary team. At the same time, a user with low privileges could exploit this vulnerability to access unauthorized data and perform actions with elevated privileges. | |
| Title | Stored Cross-Site Scripting (XSS) vulnerability in the Wakyma application web | |
| First Time appeared |
Wakyma
Wakyma wakyma Application Web |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:wakyma:wakyma_application_web:all_versions:*:*:*:*:*:*:* | |
| Vendors & Products |
Wakyma
Wakyma wakyma Application Web |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-03-16T13:25:02.460Z
Reserved: 2026-02-23T13:43:57.015Z
Link: CVE-2026-3024
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses