Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1
Critical0
High1
Medium0
Reset
Showing 1-1 of 1 records
Threat Entry Updated 2026-06-23

CVE-2026-8172 - Through 20250114 Does Not Escape User Supplied Input Plugin

The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it into the contact form output on validation errors, leading to a Reflected Cross-Site Scripting vulnerability that unauthenticated attackers can exploit against site visitors via a crafted link or cross-site form submission.

PLUGIN Through 20250114 Does Not Escape User Supplied Input

CVE-2026-8172

HIGH CVSS 7.1 2026-06-23
Scroll to top