CVE-2026-5782: Reflected XSS in Loglama.NET's TurkHotspot
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Loglama.net TurkHotspot allows Reflected XSS.
This issue affects TurkHotspot: through 2026-10-02. NOTE: The vendor was contacted and it was learned that the product is not supported.
Other sources
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Loglama.net TurkHotspot allows Reflected XSS.
This issue affects TurkHotspot: through 2026-10-02. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker needs adjacent-network access and does not need privileges. Exploitation also requires user interaction.
Which TurkHotspot versions are affected?
The issue is reported to affect Loglama.net TurkHotspot through 2026-10-02. No fixed version is identified in the available information.
Is vendor remediation available?
The vendor was contacted early about the disclosure but did not respond. The available information does not identify a patch or other vendor-provided mitigation.