Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services Website Template allows Reflected XSS.

This issue affects Website Template: before v2.
Published: 2026-07-24
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of user‑supplied data during the generation of web pages results in a reflected cross‑site scripting vulnerability. The flaw allows an attacker to deliver and execute arbitrary JavaScript within the victim’s browser session, potentially exposing or manipulating data displayed by the application, or enabling other client‑side attacks. The weakness is a failure to properly encode output (CWE‑79).

Affected Systems

All releases of Polen Media Software and Information Services’ Website Template before version 2.0 are affected; no additional sub‑version details are provided.

Risk and Exploitability

The vulnerability carries a CVSS base score of 6.1, indicating moderate severity, and an EPSS score of less than 1 %, suggesting a low likelihood of widespread exploitation. It is not listed in the CISA KEV catalog. Exploitation requires a web request that echoes user data back in the page, so a crafted URL or form field can trigger the reflected XSS. The impact is confined to the victim’s browser and the data rendered by the application in that context.

Generated by OpenCVE AI on August 4, 2026 at 15:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the website template to version 2.0 or later.
  • If an upgrade is not feasible, ensure that all user‑supplied data is properly encoded before rendering it in any HTML context.
  • Add a Content‑Security‑Policy header that restricts allowed script sources and disallows inline scripts.

Generated by OpenCVE AI on August 4, 2026 at 15:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Polen Media
Polen Media website Template
Vendors & Products Polen Media
Polen Media website Template

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services Website Template allows Reflected XSS. This issue affects Website Template: before v2.
Title Reflected XSS Polen Media's Website Template
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Polen Media Website Template
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-24T14:53:01.526Z

Reserved: 2026-05-11T12:12:23.445Z

Link: CVE-2026-8308

cve-icon Vulnrichment

Updated: 2026-07-24T14:52:57.990Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T15:19:08.187

Modified: 2026-07-24T20:47:58.773

Link: CVE-2026-8308

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')