CVE-2026-19057: Stored XSS in Gastromenum's Gastromenum Ticket and QR Menu System
Published Sep 4, 2026
·Updated
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Stored XSS.
This issue affects Gastromenum Ticket and QR Menu System: before 2026.08.31.
Affected Software
1 affected component
Gastromenum Ticket and QR Menu System<2026.08.31
Event History
Sep 4, 2026
CVE Published
via MITRE·01:52 PM
Data Sourced
via MITRE·01:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who needs to act on this issue?
Deployments of Gastromenum Ticket and QR Menu System that are running a version before 2026.08.31 are affected.
2
What level of access does an attacker need?
The vector indicates network-reachable exploitation with low privileges required. A user must also interact with attacker-controlled content for the XSS payload to take effect.