CVE-2026-92085: Stored XSS in TMT Machine's Talassoft Industrial Management Software
Published Oct 9, 2026
·Updated
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TMT Machinery Industry and Trade Co. Ltd. Talassoft Industrial Management Software allows Stored XSS.
This issue affects Talassoft Industrial Management Software: before V16.0.1.
Affected Software
1 affected component
TMT Machinery Industry and Trade Co. Ltd. Talassoft Industrial Management Software<16.0.1
Event History
Oct 9, 2026
CVE Published
via MITRE·01:26 PM
Data Sourced
via MITRE·01:26 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Talassoft Industrial Management Software versions before V16.0.1 are affected.
2
What level of access and interaction does exploitation require?
The published vector indicates an attacker needs low-privileged access and user interaction. The vulnerability is reachable over the network and has low attack complexity.
3
What is the potential impact of successful exploitation?
The severity vector indicates low confidentiality and integrity impact, no availability impact, and a changed scope.