---
id: CVE-2020-26680
title: >-
  In vFairs 3.3, any user logged in to a vFairs virtual conference or event can
  modify any other users profile information to include a cross-site scripting
  payload
summary: >-
  In vFairs 3.3, any user logged in to a vFairs virtual conference or event can
  modify any other users profile information to include a cross-site scripting
  payload. The user data stored by the database includes HTML tags that are
  intentio…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: vfairs
product: vfairs
affected:
  - vfairs = 3.3
published: '2021-05-26'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-26680'
references:
  - url: >-
      https://www.huntress.com/blog/zero-day-vulnerabilities-in-popular-event-management-platforms-could-leave-msps-open-to-attack
    label: cve@mitre.org
  - url: 'http://vfairs.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.huntress.com/blog/zero-day-vulnerabilities-in-popular-event-management-platforms-could-leave-msps-open-to-attack
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.0046
epssPercentile: 0.37293
ingestedAt: '2026-07-05T00:59:26.434Z'
---

## Overview

In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload. The user data stored by the database includes HTML tags that are intentionally rendered out onto the page, and this can be abused to perform XSS attacks.

## Affected

- `vfairs = 3.3`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
