← Vulnerability feed

Vulnerability record · CVE-2015-20116 · published 16 March 2026

CVE-2015-20116: Nextclickventures realtyscript cross-site scripting vulnerability

NNextclickventures · Realtyscript

Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize CSV file uploads, allowing attackers to inject malicious scripts through filename parameters in multipart form data. Attackers can upload files with XSS payloads in the filename field to execute arbitrary JavaScript in users' browsers when the file is processed or displayed.

5.1 CVSS 4.0 Medium EPSS 0.24% · top 86.3% CWE-79 · Cross-site scripting
5.1CVSS 4.0 base score
0.24%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize CSV file uploads, allowing attackers to inject malicious scripts through filename parameters in multipart form data. Attackers can upload files with XSS payloads in the filename field to execute arbitrary JavaScript in users' browsers when the file is processed or displayed.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-20116 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2015-20121Nextclickventures realtyscript sql injection vulnerabilityNext Click Ventures RealtyScript 4.0.2 contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by …EPSS 0.42%8.8CVE-2015-20120Nextclickventures realtyscript sql injection vulnerabilityNext Click Ventures RealtyScript 4.0.2 contains multiple time-based blind SQL injection vulnerabilities that allow unauthenticated attackers to extra…EPSS 0.42%6.9CVE-2015-20117Nextclickventures realtyscript cross-site request forgery vulnerabilityNext Click Ventures RealtyScript 4.0.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create unauthoriz…EPSS 0.19%6.9CVE-2015-20113Nextclickventures realtyscript cross-site request forgery vulnerabilityNext Click Ventures RealtyScript 4.0.2 contains cross-site request forgery and persistent cross-site scripting vulnerabilities that allow attackers t…EPSS 0.18%5.1CVE-2015-20118Nextclickventures realtyscript cross-site scripting vulnerabilityNext Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability in the location_name parameter of the admin locations int…EPSS 0.32%5.1CVE-2015-20119Nextclickventures realtyscript cross-site scripting vulnerabilityNext Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious H…EPSS 0.21%5.1CVE-2015-20114Nextclickventures realtyscript cross-site scripting vulnerabilityNext Click Ventures RealtyScript 4.0.2 contains a cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code …EPSS 0.27%5.1CVE-2015-20115Nextclickventures realtyscript cross-site scripting vulnerabilityNext Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malicious scripts through the file POST p…EPSS 0.27%

Source: NIST National Vulnerability Database (record CVE-2015-20116), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.