PatchSiren

kstover CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH kstover CVE published 2026-09-05

CVE-2026-19769

The Ninja Forms plugin for WordPress has a Stored Cross-Site Scripting vulnerability via Repeater Child 'type' Confusion due to insufficient input sanitization and output escaping. This allows unauthenticated attackers to inject web scripts when the Ninja Forms File Uploads add-on is active. The vulnerability exists in all versions up to, and including, 3.15.1 and exploitation requires the Ninja Forms Fil [truncated]