NVD HIGH: CVE-2026-73332 — CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_con...
CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to the before_html field through the contact form edit endpoint, which lacks proper authorization controls. Attackers can persist malicious script payloads into the database that execute in vic
CVE-2026-73332