What is CVE-2026-65446?
This vulnerability is an unauthenticated Cross-Site Scripting (XSS) in Kali Forms plugin versions 2.4.18 and earlier. It allows remote injection of malicious scripts on affected sites, so users should immediately update the plugin to the latest version.
Azərbaycanca: Bu boşluq Kali Forms plaginin 2.4.18 və daha əvvəlki versiyalarında autentifikasiya olmadan saxlanılan XSS (Cross-Site Scripting) zəifliyidir. Təsirə məruz qalan saytlarda uzaqdan zərərli kod yeridilə bilər, istifadəçilər plugini dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
Which versions of the Kali Forms plugin are affected by CVE-2026-65446?
Kali Forms plugin versions 2.4.18 and earlier are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.