CVE-2026-31354: XSS
Multiple authenticated stored cross-site scripting (XSS) vulnerabilities in the Permissions module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Group, Category or Description parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31354?
CVE-2026-31354 is classified as a high severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2026-31354?
To fix CVE-2026-31354, update Feehi CMS to the latest version that addresses these vulnerabilities.
What components are affected by CVE-2026-31354?
CVE-2026-31354 affects the Permissions module of Feehi CMS version 2.1.1.
What types of attacks are possible with CVE-2026-31354?
CVE-2026-31354 allows attackers to execute arbitrary web scripts or HTML through stored cross-site scripting.
Who is at risk for CVE-2026-31354?
Any user or administrator utilizing Feehi CMS v2.1.1 is at risk for being targeted by CVE-2026-31354.