PatchSiren

299ko CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM 299ko CVE published 2026-08-05

CVE-2026-71249

The 299Ko's public contact form plugin is vulnerable to reflected XSS due to lack of sanitization and htmlspecialchars() function call in the template engine's variable output function. An unauthenticated attacker can submit a payload to achieve reflected XSS against any visitor who submits or is tricked into auto-submitting the form. This vulnerability exists in the contact form's controller and template [truncated]