VYPR
Unrated severityNVD Advisory· Published Jul 2, 2026· Updated Jul 2, 2026

POST-based reflected XSS via the thanks parameter in form components

CVE-2026-14449

Description

u5CMS through v12.8.8 is vulnerable to reflected XSS via the ‘thanks’ parameter in multiple form components

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.