CVE-2026-67595
VaahCMS versions 2.0.0 through 2.3.4 contain a hidden JavaScript payload in the OTP email template that can run code in browsers that open the email. The script connects to a command‑and‑control server, logs passwords, scrapes WhatsApp Web, and can redirect or overwrite the page.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
VaahCMS 2.0.0–2.3.4, used by sites that send OTP emails.
Real-world impact
An attacker can run arbitrary code in a victim’s browser when they open the OTP email, allowing password logging, data theft from WhatsApp Web, and page manipulation.
Why this severity
The CVSS score of 9.2 reflects that the flaw allows remote code execution without authentication, with high impact on confidentiality, integrity, and availability, and is easily exploitable over the network.
What to do about it
- ›Avoid opening OTP emails from VaahCMS until a patch is released.
- ›Use an email client that does not execute JavaScript in emails.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
NVD description