SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-8308

MEDIUM · CVSS 6.1 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

The vulnerability in the Polen Media Software and Information Services Website Template prior to version 2 allows for reflected cross-site scripting (XSS) due to improper input neutralization during web page generation. This could enable attackers to execute arbitrary scripts in the context of a user's browser session, potentially leading to data theft or session hijacking. Organizations using this template should prioritize remediation to protect against potential exploitation.

CVE
CVE-2026-8308
Severity
MEDIUM
CVSS
6.1
EPSS
0.15%

Original NVD Description

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services Website Template allows Reflected XSS. This issue affects Website Template: before v2.