CVE-2026-38947: XSS
Published May 5, 2026
·Updated
FluentCMS 1.2.3 is vulnerable to Cross Site Scripting (XSS) in TextHTML plugin.
Affected Software
1 affected component
FluentCMS FluentCMS=1.2.3
Event History
May 5, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-38947?
The severity of CVE-2026-38947 is rated medium with a CVSS score of 6.1.
2
What types of attacks are possible with CVE-2026-38947?
CVE-2026-38947 allows for Cross Site Scripting (XSS) attacks through the TextHTML plugin in FluentCMS.
3
How can I fix CVE-2026-38947?
To fix CVE-2026-38947, it's recommended to update FluentCMS to the latest version that addresses this vulnerability.
4
Which versions of FluentCMS are affected by CVE-2026-38947?
FluentCMS version 1.2.3 is explicitly vulnerable to CVE-2026-38947.
5
Is user intervention required for exploiting CVE-2026-38947?
Yes, user interaction is required to exploit CVE-2026-38947 as it relies on user engagement with the affected plugin.