Two stored XSS vulnerabilities have been disclosed in the NethServer WebTop module, affecting versions 1.5.6 and earlier. CVE-2026-78331 (CVSS 4.0: 8.7) affects the calendar component, while CVE-2026-78332 (CVSS 4.0: 8.2) affects the contacts component.
Both vulnerabilities allow malicious content to be stored and JavaScript code to be executed when the affected calendar event or contact is viewed by another user. Affected versions: WebTop <= 1.5.6 Fixed version: WebTop 1.5.7 Credits: Vulnerability discovered by Andrea Intilangelo References: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-nethserver https://github.com/NethServer/ns8-webtop/security/advisories/GHSA-cqcv-5f3w-wpmr https://github.com/NethServer/ns8-webtop/security/advisories/GHSA-7vf9-f3rc-vg3x
