PatchSiren

complianz CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH complianz CVE published 2026-09-18

CVE-2026-83561

The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content. This vulnerability affects all versions up to, and including, 7.5.4 due to insufficient input sanitization and output escaping. Successful exploitation requires an administrator to approve the attacker's comment, and the site must have both the Elementor plugin installed and [truncated]

MEDIUM Complianz CVE published 2026-07-23

CVE-2026-65498

The Complianz plugin version 7.5.0 or earlier has an unauthenticated sensitive data exposure vulnerability. This vulnerability, tracked as CVE-2026-65498, has a CVSS score of 5.3 and is classified as medium severity. The vulnerability was published on 2026-07-23T12:18:43.160Z. Administrators and users of Complianz plugin version 7.5.0 or earlier should be aware of this vulnerability and take necessary act [truncated]