CVE-2021-47926Disclosure

LOWCVSS 5.1 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Contact Form to Email 1.3.24 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating forms with script tags in the form name field. Attackers can craft form names containing JavaScript code that executes when other logged-in users access the form management page, enabling session hijacking or credential theft.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-10: 2Patch / Workaround · 2026-05-10: 1Technical Details · 2026-05-10: 205-10
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Entity@0x2ed3bb60
    Patch

    🚨 Entity detected CVE-2021-47926 in Contact Form to Email 1.3.24. Stored XSS via form name field. Authenticated attackers inject scripts, execute on admin access. Session hijacking vector confirmed. Patch immediately. https://0x2ed3bb60.xyz/threat/099d5f7489090339

    Post summary

    CVE‑2021‑47926 is a stored XSS in Contact Form to Email 1.3.24, requiring authenticated admin access; the vulnerability can enable session hijacking and a patch is immediately advised.

    0003040
    7 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2021-47926 Contact Form to Email 1.3.24 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating forms wi… https://www.cve.org/CVERecord?id=CVE-2021-47926

    Post summary

    CVE‑2021‑47926 reveals a stored XSS flaw in Contact Form to Email 1.3.24 that lets authenticated users inject malicious scripts through form creation.

    0000075
    57.5K followersView on X

Explore more