ZeroHour

CVE-2026-52307

PoC niche

Authenticated Stored XSS in ClassCMS 1CMS v5.6 Column Management

CVSS 3.1
5.4 medium
EPSS
<1%p19
Published
()
Modified
AI analysis

CVE-2026-52307 is an authenticated stored cross-site scripting (XSS) flaw in the Column Management component of ClassCMS 1CMS v5.6. An authenticated user can inject a crafted payload into the title field of a column, which is then stored and executed as arbitrary web scripts or HTML when other users view the affected content. Successful exploitation allows the attacker to run attacker-controlled scripts in the browsers of users who view the injected column, potentially enabling actions such as session hijacking or performing actions under victims' credentials. Only deployments of 1CMS v5.6 are identified as affected in the disclosure. There is no confirmed in-the-wild exploitation: the flaw is not in CISA KEV, EPSS estimates only a 0.3% probability of exploitation in the next 30 days, and one public proof-of-concept reference exists on GitHub.

What to do: Audit whether you run 1CMS and confirm the version; operators of v5.6 should restrict which authenticated accounts can edit column titles and sanitize/validate title input as an interim mitigation. Watch the vendor and the referenced PoC (github.com/linan-OO/CVE-2026-52307) for a patched release, and upgrade as soon as a fixed version is published, since no fixed version is specified in the current disclosure. Given the low EPSS score, absence from CISA KEV, and the authentication requirement, treat this as a lower-priority patch pending vendor guidance.

Affected
ClassCMS 1CMSv5.6 (specific version cited in the disclosure; broader affected version ranges not specified)
Estimated exposure
nicheunknown (no public active-install counts or scan data for ClassCMS 1CMS); deployment base is plausibly in the thousands of sites at most — No public active-install counts, market-share figures, or internet-exposure scan data exist for ClassCMS 1CMS, a low-adoption CMS, so only a qualitative 'niche' classification is supportable and the count is treated as unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An authenticated stored cross-site scripting (XSS) vulnerability in the Column Management component of ClassCMS 1CMS v5.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the title field.

Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

CVE-2026-52307: Stored XSS in 1CMS v5.6

CVE-2026-52307: authenticated stored XSS in 1CMS (ClassCMS) v5.6 Column Management lets attackers inject scripts via the title field.

ClassCMS 1CMS v5.6 contains an authenticated stored cross-site scripting vulnerability, CVE-2026-52307, in the Column Management component. Attackers can execute arbitrary web scripts or HTML by injecting a crafted payload into the title field. No CVSS score, patch information, or exploitation evidence was provided in the disclosure.

Full Disclosure · 7d agoVulnerabilityCVE-2026-52307