Cozystay · Cozystay · CVE-2026-78289
**Name of the Vulnerable Software and Affected Versions**
CozyStay versions prior to 1.10.1
**Description**
Unauthenticated Cross Site Scripting (XSS) allows an attacker to execute malicious scripts in the browser of a user without requiring authentication.
**Recommendations**
Update CozyStay to a version newer than 1.10.0.