
CVE-2026-32757 Admidio is an open-source user management solution. In versions 5.0.6 and below, the eCard send handler uses a raw $_POST['ecard_message'] value instead of the HTMLPu… https://www.cve.org/CVERecord?id=CVE-2026-32757
Post summary
A CVE-2026-32757 vulnerability in Admidio’s eCard handler is disclosed, highlighting the unsanitized use of $_POST['ecard_message']. No PoC, exploit code, patch, or evidence of active exploitation is present.
