PatchSiren

Metaphor Creations CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Metaphor Creations CVE published 2026-09-21

CVE-2026-93339

A stored cross-site scripting vulnerability exists in Metaphor Creations Ditty (ditty-news-ticker) before version 3.1.70. Authenticated users with Author-level privileges or higher can inject arbitrary HTML elements by supplying malicious wrapper attribute values in layout tags. The ditty_layout_render_tag_wrapper() function directly inserts caller-supplied wrapper attribute values as HTML element names w [truncated]