CVE-2026-9588
A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification tem
CVSS
—
No CVSS
EPSS
0.4%
p35
KEV
—
Exploit Today
10
0-100
Published: Jul 17, 2026 · Last modified: Jul 17, 2026 · CWE-79
0.4%EPSS · 30 days0.4%
2026-08-252026-09-23
A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality. The submit_modify_voicemail_template endpoint fails to properly sanitize HTML content supplied by authenticated users, allowing malicious JavaScript supplied through the template_text parameter to be stored server-side and subsequently rendered to other users.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-955866.5 MED—
——0Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions.3hCVE-2026-955306.5 MED—
——0Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions.3hCVE-2026-955297.1 HIG—
——0Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions.3hCVE-2026-955287.1 HIG—
——0Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions.3hCVE-2026-955157.1 HIG—
——0Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.3hCVE-2026-946846.5 MED—
——0Contributor Cross Site Scripting (XSS) in Ocean Extra <= 2.6.1 versions.3h