PatchSiren

telepathy CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM telepathy CVE published 2026-04-08

CVE-2026-39666

A DOM-Based XSS vulnerability was found in Hello Bar Popup Builder, affecting versions from n/a through <= 1.5.1. This Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability has a MEDIUM CVSS severity score of 6.5. Limited evidence is available, and further verification is required by users and defenders. The CVE record was published on 2026-04-08T09:16:37.893Z [truncated]