PatchSiren

onSite internet GmbH CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW onSite internet GmbH CVE published 2026-09-23

CVE-2026-96258

A vulnerability was found in onSite internet GmbH Auktion NG Auktionssoftware up to 20260722, affecting the Public Password Reset Endpoint. The manipulation of the email argument leads to cross-site scripting. This issue can be exploited remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted but did not respond.