CVE-2026-52307: Stored XSS in 1CMS v5.6
CVE-2026-52307: authenticated stored XSS in 1CMS (ClassCMS) v5.6 Column Management lets attackers inject scripts via the title field.
ClassCMS 1CMS v5.6 contains an authenticated stored cross-site scripting vulnerability, CVE-2026-52307, in the Column Management component. Attackers can execute arbitrary web scripts or HTML by injecting a crafted payload into the title field. No CVSS score, patch information, or exploitation evidence was provided in the disclosure.
- CVE-2026-52307: authenticated stored XSS in Column Management
- Payload injected via the title field executes in browsers
- Affects 1CMS (ClassCMS) version 5.6
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-52307 | Authenticated Stored XSS in ClassCMS 1CMS v5.6 Column Management CVE-2026-52307 is an authenticated stored cross-site scripting (XSS) flaw in the Column Management component of ClassCMS 1CMS v5.6. An authenticated user can inject a crafted payload into the title field of a column, which is then stored and executed as arbitrary web scripts or HTML when other users view the affected content. Successful exploitation allows the attacker to run attacker-controlled scripts in the browsers of users who view the injected column, potentially enabling actions such as session hijacking or performing actions under victims' credentials. Only deployments of 1CMS v5.6 are identified as affected in the disclosure. There is no confirmed in-the-wild exploitation: the flaw is not in CISA KEV, EPSS estimates only a 0.3% probability of exploitation in the next 30 days, and one public proof-of-concept reference exists on GitHub. Do: Audit whether you run 1CMS and confirm the version; operators of v5.6 should restrict which authenticated accounts can edit column titles and sanitize/validate title input as an interim mitigation. Watch the vendor and the referenced PoC (github.com/linan-OO/CVE-2026-52307) for a patched release, and upgrade as soon as a fixed version is published, since no fixed version is specified in the current disclosure. Given the low EPSS score, absence from CISA KEV, and the authentication requirement, treat this as a lower-priority patch pending vendor guidance. | 5.4 | <1% | PoC |
| nicheunknown (no public active-install counts or scan data for ClassCMS 1CMS); deployment base is plausibly in the thousands of sites at most |
Posted by 懒-癌-症~ via Fulldisclosure on Sep 08 CVE-2026-52307: 1CMS v5.6 Authenticated Stored XSS Vulnerability Vulnerability Description An authenticated stored cross-site scripting (XSS) vulnerability exists in the Column Management component of ClassCMS 1CMS v5.6. Attackers can execute arbitrary web scripts or HTML by injecting a crafted payload into the title field. - Vulnerability Type: Cross Site Scripting (XSS) - Vendor: ClassCMS - Affected Product: 1CMS v5.6 - Affected Component:...
This source does not provide full text. Read it at seclists.org.