PatchSiren

Open ISES CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Open ISES CVE published 2026-05-21

CVE-2026-48224

CVE-2026-48224 is a reflected cross-site scripting flaw in the Open ISES Tickets project’s ics214.php handler. The supplied corpus says unsanitized frm_add_str POST data can be copied into an HTML hidden input value attribute, allowing attacker-supplied JavaScript to execute when the response is rendered. The issue is tied to the v3.44.2 release and a corresponding GitHub fix commit, while the NVD record [truncated]

MEDIUM Open ISES CVE published 2026-05-21

CVE-2026-48223

CVE-2026-48223 is a reflected cross-site scripting issue in Open ISES Tickets affecting versions before 3.44.2. The flaw is tied to ics213rr.php, where an unsanitized frm_add_str POST parameter is placed directly into a hidden input value attribute, enabling JavaScript execution in a victim’s browser when the crafted response is rendered. The vulnerability was published on 2026-05-21 and NVD later listed [truncated]

MEDIUM Open ISES CVE published 2026-05-21

CVE-2026-48222

CVE-2026-48222 is a reflected cross-site scripting issue in Open ISES Tickets before version 3.44.2. An authenticated attacker can place unsanitized input from the frm_add_str POST parameter into a hidden HTML input value in ics213.php, causing arbitrary JavaScript to execute when the page is rendered in a victim's browser. The reported CVSS severity is medium, and the flaw is categorized as CWE-79.

MEDIUM Open ISES CVE published 2026-05-21

CVE-2026-48221

CVE-2026-48221 describes a reflected cross-site scripting issue in Open ISES Tickets affecting ics205a.php before version 3.44.2. The problem centers on the frm_add_str POST parameter being passed into an HTML hidden input value attribute without proper sanitization, allowing attacker-supplied script content to be reflected into the page. Vulnerability references point to a fixing commit and the v3.44.2 r [truncated]

MEDIUM Open ISES CVE published 2026-05-21

CVE-2026-48220

CVE-2026-48220 describes a reflected cross-site scripting issue in Open ISES Tickets versions before 3.44.2. The vulnerable path is ics205.php, where the frm_add_str POST parameter is passed into an HTML hidden input value without sanitization. In practice, an authenticated attacker can submit a crafted request that causes arbitrary JavaScript to execute when the response is rendered in a victim’s browser [truncated]

MEDIUM Open ISES CVE published 2026-05-21

CVE-2026-48219

CVE-2026-48219 covers a reflected cross-site scripting (XSS) issue in Open ISES Tickets before version 3.44.2. The vulnerable path is ics202.php, where an unsanitized value from the frm_add_str POST parameter is placed into an HTML hidden input value attribute. An authenticated attacker can supply a crafted request that causes browser-side JavaScript to execute when the response is rendered. NVD published [truncated]

MEDIUM Open ISES CVE published 2026-05-21

CVE-2026-48218

CVE-2026-48218 was published on 2026-05-21 and describes a reflected cross-site scripting issue in Open ISES Tickets before version 3.44.2. The vulnerable path is icons/buttons/landb.php, where unsanitized frm_name and frm_id POST parameters are reflected into rendered HTML and inline JavaScript. The supplied sources indicate a fix is associated with the 3.44.2 release and a related code commit. NVD marke [truncated]

MEDIUM Open ISES CVE published 2026-05-21

CVE-2026-48217

CVE-2026-48217 is a reflected cross-site scripting issue in Open ISES Tickets, affecting versions before 3.44.2. The flaw is in delete_module.php, where unsanitized POST inputs can flow into rendered HTML and form action attributes. Because the payload is executed in the browser when the response is rendered, an attacker with authentication and a way to induce a victim to load the crafted response could e [truncated]

MEDIUM Open ISES CVE published 2026-05-21

CVE-2026-48216

CVE-2026-48216 is a reflected cross-site scripting issue reported in Open ISES Tickets before version 3.44.2. The issue is described as unsanitized POST parameters being inserted into HTML input value attributes in db_loader.php, allowing attacker-controlled JavaScript to run in a victim’s browser when the response is rendered. The published fix is associated with the v3.44.2 release and a linked repository commit.

MEDIUM Open ISES CVE published 2026-05-21

CVE-2026-48215

CVE-2026-48215 is a reflected cross-site scripting issue in Open ISES Tickets before 3.44.2. Authenticated attackers can pass an unsanitized frm_id value to circle.php, where it is reflected into an HTML form input value attribute and can execute JavaScript in a victim's browser when the response is rendered. The issue is tracked by NVD with a published date of 2026-05-21 and references a fix commit plus [truncated]

MEDIUM Open ISES CVE published 2026-05-21

CVE-2026-48214

CVE-2026-48214 is a reflected cross-site scripting vulnerability reported in Open ISES Tickets before version 3.44.2. The issue affects add_nm.php, where an unsanitized ticket_id POST parameter can be reflected into an HTML form input value attribute and an inline JavaScript string literal. An authenticated attacker can cause malicious script to run in a victim’s browser when the crafted response is rendered.

MEDIUM Open ISES CVE published 2026-05-21

CVE-2026-48213

CVE-2026-48213 is a reflected cross-site scripting issue in Open ISES Tickets prior to version 3.44.2. The problem is in add.php, where an unsanitized ticket_id POST value is inserted into an HTML form input value attribute. An authenticated attacker can send a crafted request so that malicious JavaScript executes in the victim’s browser when the response is rendered.