MEDIUM
299ko
CVE published 2026-08-05
CVE-2026-71249
The 299Ko's public contact form plugin is vulnerable to reflected XSS due to lack of sanitization and htmlspecialchars() function call in the template engine's variable output function. An unauthenticated attacker can submit a payload to achieve reflected XSS against any visitor who submits or is tricked into auto-submitting the form. This vulnerability exists in the contact form's controller and template [truncated]