THREATOPS
THREAT OPSThreat News › CVE-2026-52307: Stored XSS in 1CMS v5.6

CVE-2026-52307: Stored XSS in 1CMS v5.6

medfulldisclosurePublished 2026-09-08

<p>Posted by 懒-癌-症~ via Fulldisclosure on Sep 08</p>CVE-2026-52307: 1CMS v5.6 Authenticated Stored XSS Vulnerability<br /> <br /> Vulnerability Description<br /> An authenticated stored cross-site scripting (XSS) vulnerability exists in the Column Management component of ClassCMS <br /> 1CMS v5.6. Attackers can execute arbitrary web scripts or HTML by injecting a crafted payload into the title fie

Indicators of compromise

Original source: https://seclists.org/fulldisclosure/2026/Sep/31