CVE-2026-67595
VaahCMS Malicious JavaScript in OTP Email Templates
Halo Surface Signal: 3 out of 5 — possibly public-facing.
VaahCMS contains malicious JavaScript in its security email templates, which could execute code in a user's browser and capture sensitive information if the emails are rendered with JavaScript enabled. The vulnerability allows remote attackers to establish unauthorized WebSocket connections, install keyloggers, and scr