CVE-2026-73329

Source
https://cve.org/CVERecord?id=CVE-2026-73329
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73329.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-73329
Published
2026-08-12T18:54:07.352Z
Modified
2026-08-15T04:07:09.102584241Z
Severity
  • 9.2 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N CVSS Calculator
Summary
CamaleonCMS Stored XSS via Draft Post Title Creation Endpoint
Details

CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an administrator's browser by injecting unsanitized HTML payloads into the post title parameter during draft creation. Attackers can submit a malicious HTML payload as a draft title through the drafts creation endpoint, which is persisted to the database without escaping and later rendered as raw HTML in the admin drafts listing, enabling administrator session compromise, cookie theft, and forged authenticated requests.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73329.json",
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/owen2345/camaleon-cms

Affected ranges

Type
GIT
Repo
https://github.com/owen2345/camaleon-cms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.9.1"
        }
    ]
}

Affected versions

0.*
0.1.7
0.2.0
2.*
2.1.1
2.1.2
2.1.2.0
2.2.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.4.0
2.4.1
2.4.2
2.4.3
2.4.3.10
2.4.3.11
2.4.3.12
2.4.3.7
2.4.4
2.4.4.2
2.4.4.3
2.4.4.5
2.4.4.6
2.4.5
2.4.5.1
2.4.5.10
2.4.5.11
2.4.5.12
2.4.5.13
2.4.5.14
2.4.5.7
2.4.6.0
2.4.6.1
2.4.6.7
2.5.1
2.5.3
2.5.3.1
2.6.0
2.6.0.1
2.6.1
2.6.2
2.6.4
2.7.0
2.7.1
2.7.3
2.7.4
2.7.5
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.1
camaleon_cms-2.*
camaleon_cms-2.4.5.11.gem
v2.*
v2.0.0
v2.1.1.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73329.json"