Junglewise Threat Intelligence

CVE-2026-8308: Polen Media Website Template reflected XSS

CVE-2026-8308 · Severity: medium · CVSS 6.1 · Published 2026-07-24

Executive brief

Polen Media Website Template, a software package used to build and deploy business websites, contains a security flaw that allows for cross-site scripting. An attacker can trick a user into clicking a malicious link, which then executes unauthorized code in the user's browser. This could lead to the theft of login cookies, session hijacking, or the display of fraudulent content to the website's visitors.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the Polen Media Software and Information Services Website Template prior to version 2. The flaw is caused by improper neutralization of input during web page generation (CWE-79), allowing an unauthenticated remote attacker to inject malicious scripts into a victim's browser. Exploitation requires a user to interact with a specially crafted URL. Successful exploitation can result in the execution of arbitrary JavaScript in the context of the victim's session, potentially leading to credential theft or session hijacking. The issue is addressed in version 2 of the template.

Affected products

  • Polen Media Software and Information Services Website Template before v2

Timeline

  • 2026-07-24: advisory: Published by NVD and TR-CERT

References