CVE-2026-78268Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-497

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-24: 3Technical Details · 2026-08-24: 208-24
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-78268 Unauthenticated Sensitive Data Exposure in SiteLeads Chat Widget and AI Chatbot &lt;= 1.2.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-78268

    Post summary

    The text announces a newly identified vulnerability (CVE-2026-78268) in SiteLeads Chat Widget and AI Chatbot, but provides no technical or exploit details beyond the basic exposure claim.

    00000136
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-78268 Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads &lt;= 1.2.0 versions. https://www.cve.org/CVERecord?id=CVE-2026-78268 ----- Traducción: CVE-2026-78268 Exposición d… https://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑78268, describing it as an unauthenticated sensitive data exposure in specific components, but does not provide a PoC, exploit, active exploitation evidence, or patch information.

    0000040
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-78268 Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp;amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads &lt;= 1.2.0 versions. https://www.cve.org/CVERecord?id=CVE-2026-78268

    Post summary

    The text announces CVE‑2026‑78268, detailing an unauthenticated sensitive data exposure in SiteLeads widgets up to version 1.2.0, but it provides no PoC, exploit, patch, or active exploitation information.

    000001.1K
    58.0K followersView on X

Explore more