PT-2026-68857 · Unknown · Subscribe2

·

CVE-2026-14331

·

Published

2026-08-07

·

Updated

2026-08-07

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Subscribe2 versions prior to 10.46
Description Insufficient escaping of user-supplied values before they are reflected into a public subscription form allows Reflected Cross-Site Scripting (XSS). This occurs when an unauthenticated visitor interacts with the form via a crafted link, executing malicious scripts in their browser. The issue is triggered through the email parameter.
Recommendations Update Subscribe2 to version 10.46 or later. Avoid using the email parameter in the subscription form until the update is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14331

Affected Products

Subscribe2