GHSA-m5p6-p4r7-5mqxMediumCVSS 5.4

An authenticated stored cross-site scripting (XSS) vulnerability in the Column Management...

Published
September 8, 2026
Last Modified
September 14, 2026

🔗 CVE IDs covered (1)

📋 Description

An authenticated stored cross-site scripting (XSS) vulnerability in the Column Management component of ClassCMS 1CMS v5.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the title field.

🔗 References (5)