CVE-2026-8308 Details
Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services Website Template allows Reflected XSS. This issue affects Website Template: before v2.
A reflected cross-site scripting vulnerability has been identified in the Polen Media Software and Information Services Website Template, affecting versions prior to 2.0. This issue arises from improper neutralization of input during web page generation, allowing attackers to inject malicious scripts that are executed in the context of the user's browser.
Users are advised to upgrade to version 2.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 24, 2026CISA-ADP
Assessed Jul 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0635 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Polen Media Software and Information Services Website Template | < 2 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | New CVE Received | [email protected] |
| Jul 24, 2026 | CVE Modified | CISA-ADP |
Volerion