CVE-2026-88746: XSS
Published Sep 21, 2026
·Updated
idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/makeDiydeal.php.
Affected Software
1 affected component
idccms=1.70
Event History
Sep 21, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:17 PM
Description
Frequently Asked Questions
1
How can I determine whether this applies to my deployment?
Check whether the deployment is running idccms V1.70 and includes the /admin/makeDiy_deal.php endpoint. The provided information does not identify affected versions other than V1.70.
2
Does the available information specify authentication requirements or a workaround?
No. The provided data does not state whether an attacker must authenticate, which input triggers the XSS, whether default configurations are affected, or any mitigation when patching is unavailable.