
CVE-2026-71249 299Ko's public contact form (plugin/contact/controllers/ContactController.php, home()) sets raw POST field values (name, firstname, email, message) into the page temp… https://www.cve.org/CVERecord?id=CVE-2026-71249
Post summary
The text discloses CVE‑2026‑71249 involving raw POST data handling in 299Ko's contact form, indicating a potential injection flaw, but reports no active exploitation, patch, or PoC.


