CVE-2026-73332

critical

Description

CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to the before_html field through the contact form edit endpoint, which lacks proper authorization controls. Attackers can persist malicious script payloads into the database that execute in victims' browsers when the contact form loads, enabling cookie theft, forged authenticated requests against the admin interface, and session takeover of viewing users.

References

https://www.vulncheck.com/advisories/camaleoncms-cama-contact-form-plugin-stored-xss-via-before-html-field

https://github.com/owen2345/camaleon-cms

https://enrik-m.github.io/posts/Camaleon-CMS-Vulnerabilties/#32-stored-xss-in-contact-form

Details

Source: Mitre, NVD

Published: 2026-08-12

Updated: 2026-08-12

Risk Information

CVSS v2

Base Score: 8.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:N

Severity: High

CVSS v3

Base Score: 8.7

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Severity: High

CVSS v4

Base Score: 9.2

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

Severity: Critical