These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-48224 is a reflected cross-site scripting flaw in the Open ISES Tickets project’s ics214.php handler. The supplied corpus says unsanitized frm_add_str POST data can be copied into an HTML hidden input value attribute, allowing attacker-supplied JavaScript to execute when the response is rendered. The issue is tied to the v3.44.2 release and a corresponding GitHub fix commit, while the NVD record [truncated]
CVE-2026-48223 is a reflected cross-site scripting issue in Open ISES Tickets affecting versions before 3.44.2. The flaw is tied to ics213rr.php, where an unsanitized frm_add_str POST parameter is placed directly into a hidden input value attribute, enabling JavaScript execution in a victim’s browser when the crafted response is rendered. The vulnerability was published on 2026-05-21 and NVD later listed [truncated]
CVE-2026-48222 is a reflected cross-site scripting issue in Open ISES Tickets before version 3.44.2. An authenticated attacker can place unsanitized input from the frm_add_str POST parameter into a hidden HTML input value in ics213.php, causing arbitrary JavaScript to execute when the page is rendered in a victim's browser. The reported CVSS severity is medium, and the flaw is categorized as CWE-79.
CVE-2026-48221 describes a reflected cross-site scripting issue in Open ISES Tickets affecting ics205a.php before version 3.44.2. The problem centers on the frm_add_str POST parameter being passed into an HTML hidden input value attribute without proper sanitization, allowing attacker-supplied script content to be reflected into the page. Vulnerability references point to a fixing commit and the v3.44.2 r [truncated]
CVE-2026-48220 describes a reflected cross-site scripting issue in Open ISES Tickets versions before 3.44.2. The vulnerable path is ics205.php, where the frm_add_str POST parameter is passed into an HTML hidden input value without sanitization. In practice, an authenticated attacker can submit a crafted request that causes arbitrary JavaScript to execute when the response is rendered in a victim’s browser [truncated]
CVE-2026-48219 covers a reflected cross-site scripting (XSS) issue in Open ISES Tickets before version 3.44.2. The vulnerable path is ics202.php, where an unsanitized value from the frm_add_str POST parameter is placed into an HTML hidden input value attribute. An authenticated attacker can supply a crafted request that causes browser-side JavaScript to execute when the response is rendered. NVD published [truncated]
CVE-2026-48218 was published on 2026-05-21 and describes a reflected cross-site scripting issue in Open ISES Tickets before version 3.44.2. The vulnerable path is icons/buttons/landb.php, where unsanitized frm_name and frm_id POST parameters are reflected into rendered HTML and inline JavaScript. The supplied sources indicate a fix is associated with the 3.44.2 release and a related code commit. NVD marke [truncated]
CVE-2026-48217 is a reflected cross-site scripting issue in Open ISES Tickets, affecting versions before 3.44.2. The flaw is in delete_module.php, where unsanitized POST inputs can flow into rendered HTML and form action attributes. Because the payload is executed in the browser when the response is rendered, an attacker with authentication and a way to induce a victim to load the crafted response could e [truncated]
CVE-2026-48216 is a reflected cross-site scripting issue reported in Open ISES Tickets before version 3.44.2. The issue is described as unsanitized POST parameters being inserted into HTML input value attributes in db_loader.php, allowing attacker-controlled JavaScript to run in a victim’s browser when the response is rendered. The published fix is associated with the v3.44.2 release and a linked repository commit.
CVE-2026-48215 is a reflected cross-site scripting issue in Open ISES Tickets before 3.44.2. Authenticated attackers can pass an unsanitized frm_id value to circle.php, where it is reflected into an HTML form input value attribute and can execute JavaScript in a victim's browser when the response is rendered. The issue is tracked by NVD with a published date of 2026-05-21 and references a fix commit plus [truncated]
CVE-2026-48214 is a reflected cross-site scripting vulnerability reported in Open ISES Tickets before version 3.44.2. The issue affects add_nm.php, where an unsanitized ticket_id POST parameter can be reflected into an HTML form input value attribute and an inline JavaScript string literal. An authenticated attacker can cause malicious script to run in a victim’s browser when the crafted response is rendered.
CVE-2026-48213 is a reflected cross-site scripting issue in Open ISES Tickets prior to version 3.44.2. The problem is in add.php, where an unsanitized ticket_id POST value is inserted into an HTML form input value attribute. An authenticated attacker can send a crafted request so that malicious JavaScript executes in the victim’s browser when the response is rendered.