PatchSiren

SOGO CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review SOGO CVE published 2026-08-30

CVE-2026-14835

The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 is vulnerable to stored JavaScript execution due to lack of sanitization and escaping of custom header/footer script values. This vulnerability allows users with contributor-level access to store malicious JavaScript that executes in the browser of administrators and visitors. The CVE record was published on 2026-08-30T07:1 [truncated]