CVE-2026-52307: Stored XSS in 1CMS v5.6
Posted by 懒-癌-症~ via Fulldisclosure on Sep 08CVE-2026-52307: 1CMS v5.6 Authenticated Stored XSS Vulnerability Vulnerability Description
An authenticated stored cross-site scripting (XSS) vulnerability exists in the Column Management component of ClassCMS
1CMS v5.6. Attackers can execute arbitrary web scripts or HTML by injecting a crafted payload into the title field. - Vulnerability Type: Cross Site Scripting (XSS)
- Vendor: ClassCMS
- Affected Product: 1CMS v5.6
- Affected Component:...