---
id: CVE-2026-77818
title: >-
  Improper neutralization of input during web page generation ('cross-site
  scripting') vulnerability in Yordam Information Technology Consulting,
  Training and Electronic Systems Industry and Trade Inc
summary: >-
  Improper neutralization of input during web page generation ('cross-site
  scripting') vulnerability in Yordam Information Technology Consulting,
  Training and Electronic Systems Industry and Trade Inc. Library Information
  and Document Auto…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-09-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T14:12:48.213'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77818'
references:
  - url: 'https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1011'
    label: iletisim@usom.gov.tr
tags:
  - nvd
  - exploit-available
epss: 0.00253
epssPercentile: 0.14913
exploits:
  github: 1
  githubRepos:
    - >-
      https://github.com/alkimcoskun/Yordam-Kutuphane-Otomasyonunda-Coklu-HTML-Enjeksiyonu
  checkedAt: '2026-09-25T08:21:14.168Z'
exploitAvailable: true
ingestedAt: '2026-09-08T15:33:26.960Z'
---

## Overview

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Content Spoofing.

This issue affects Library Information and Document Automation Program: from v22.1 before v22.2.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
