CVE-2026-52307: XSS
Published Sep 8, 2026
·Updated
An authenticated stored cross-site scripting (XSS) vulnerability in the Column Management component of ClassCMS 1CMS v5.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the title field.
Affected Software
1 affected component
ClassCMS 1CMS=5.6
Event History
Sep 8, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:18 PM
Description
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must be authenticated and able to submit a crafted value to the Column Management title field.
2
Where is the malicious payload stored and triggered?
The payload is injected into the title field in the Column Management component and is stored there. It can execute as web script or HTML when the stored title is later rendered.
3
Which product version is identified as affected?
The reported affected version is ClassCMS 1CMS v5.6.