PatchSiren

Form2email CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Form2email CVE published 2026-05-10

CVE-2021-47926

CVE-2021-47926 describes a stored cross-site scripting vulnerability in Contact Form to Email 1.3.24. According to the supplied record, an authenticated attacker can create a form with script content in the form name field, and that payload may execute when other logged-in users open the form management page. The expected impact is unauthorized script execution in an administrative context, which can expo [truncated]