---
id: CVE-2026-11757
title: >-
  Improper neutralization of input during web page generation ('cross-site
  scripting') vulnerability in KA Informatics Technologies Ltd
summary: >-
  Improper neutralization of input during web page generation ('cross-site
  scripting') vulnerability in KA Informatics Technologies Ltd. Co. Bar
  Association Website allows Reflected XSS.


  This issue affects Bar Association Website: through…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: KA Informatics Technologies Ltd. Co.
product: Bar Association Website
affected:
  - bar_association_website <= 18092026
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T20:17:04.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-11757'
references:
  - url: 'https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1134'
    label: iletisim@usom.gov.tr
tags:
  - nvd
  - cve.org
epss: 0.00181
epssPercentile: 0.06898
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T19:14:42.984985Z'
ingestedAt: '2026-09-18T08:38:04.097Z'
---

## Overview

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics Technologies Ltd. Co. Bar Association Website allows Reflected XSS.

This issue affects Bar Association Website: through 18092026. 
NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
