PatchSiren

JetFormBuilder CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM JetFormBuilder CVE published 2026-09-05

CVE-2026-19861

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other recipients. This vulnerability can lead to potential HTML injection in email notifications, impact [truncated]