VYPR

cama_contact_form

by CamaleonCMS

CVEs (1)

  • CVE-2026-73332HigAug 12, 2026
    risk 0.57cvss 8.7epss

    CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to the before_html field through the contact form edit endpoint, which…