Stored Cross-Site Scripting Vulnerability in CamaleonCMS Contact Form Plugin
CVE-2026-73332
9.2CRITICAL
What is CVE-2026-73332?
A stored cross-site scripting vulnerability exists in the cama_contact_form plugin of CamaleonCMS that allows attackers with low privileges to inject arbitrary HTML and JavaScript code. Attackers can exploit this flaw by submitting unsanitized input into the before_html field via the contact form edit endpoint. This vulnerability lacks sufficient authorization controls, enabling attackers to persist malicious scripts in the database. When the contact form is accessed by users, these scripts execute within their browsers, leading to potential cookie theft, unauthorized administrative actions, and session hijacking.
Affected Version(s)
CamaleonCMS 0 <= 2.9.1
