CVE-2026-71249
299Ko - Unauthenticated Reflected XSS in Public Contact Form
CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th
299Ko's public contact form (plugin/contact/controllers/ContactController.php, home) sets raw POST field values (name, firstname, email, message) into the page template with no sanitization. The template engine's variable output function (common/Template.php, _show_var) echoes values with no htmlspecialchars call, and the sink template (contact.tpl) outputs these values unescaped into an HTML attribute and a textarea.
| CWE | CWE-79 |
| Vendor | 299ko |
| Product | 299ko |
| Published | Aug 5, 2026 |
| Last Updated | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for 299ko 299ko
Be the first to know when new medium vulnerabilities affecting 299ko 299ko are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
299ko / 299Ko
0
References
Credits
Javokhir Tursunboyev