CVE-2026-4510: PbootCMS Parameter MemberController.php alert_location cross site scripting
A weakness has been identified in PbootCMS up to 3.2.12. This impacts the function alertlocation of the file apps/home/controller/MemberController.php of the component Parameter Handler. This manipulation of the argument backurl causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4510?
The severity of CVE-2026-4510 is considered moderate due to its cross-site scripting vulnerability.
How do I fix CVE-2026-4510?
You can fix CVE-2026-4510 by upgrading PbootCMS to version 3.2.13 or later.
What is affected by CVE-2026-4510?
CVE-2026-4510 affects PbootCMS versions up to and including 3.2.12, specifically the MemberController.php file.
What type of vulnerability is CVE-2026-4510?
CVE-2026-4510 is a cross-site scripting (XSS) vulnerability involving parameter manipulation.
Who is impacted by CVE-2026-4510?
Users of PbootCMS versions up to 3.2.12 are impacted by CVE-2026-4510 due to the potential for exploitation.