CVE-2026-36358: XSS
Published May 6, 2026
·Updated
Cross Site Scripting vulnerability in Juzaweb CMS v.5.0.0 allows a remote attacker via execute arbitrary code via a crafted script to the Add Banner Ads function
Affected Software
1 affected component
juzaweb juzaweb CMS=5.0.0
Event History
May 6, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-36358?
CVE-2026-36358 is considered a high-severity vulnerability due to its potential for remote code execution via Cross-Site Scripting.
2
How do I fix CVE-2026-36358?
To fix CVE-2026-36358, update to a version of Juzaweb CMS later than 5.0.0 that addresses this vulnerability.
3
What software is affected by CVE-2026-36358?
CVE-2026-36358 affects Juzaweb CMS version 5.0.0.
4
What type of vulnerability is CVE-2026-36358?
CVE-2026-36358 is a Cross-Site Scripting (XSS) vulnerability.
5
How can attackers exploit CVE-2026-36358?
Attackers can exploit CVE-2026-36358 by sending crafted scripts to the Add Banner Ads function, allowing execution of arbitrary code.