CVE-2026-52307
Deferred Deferred - Pending Action

Stored XSS in ClassCMS 1CMS v5.6 Column Management

Vulnerability report for CVE-2026-52307, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-14

Assigner: MITRE

Description

An authenticated stored cross-site scripting (XSS) vulnerability in the Column Management component of ClassCMS 1CMS v5.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the title field.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
classcms 1cms 5.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-52307 is a stored cross-site scripting (XSS) vulnerability in 1CMS v5.6's Column Management component. An authenticated administrator can inject malicious JavaScript into the article title field. When other users view the article list or detail page, the injected script executes in their browsers.

Detection Guidance

To detect this vulnerability, inspect the article title field in the Column Management component of 1CMS v5.6 for any injected JavaScript or HTML payloads. Check server logs for unusual requests to the Article Edit page. Use browser developer tools to monitor network requests and responses for suspicious scripts in the title field.

Impact Analysis

This vulnerability allows attackers to execute arbitrary scripts in users' browsers. Potential impacts include session hijacking, stealing sensitive information, phishing attacks, and defacing the website. Users with admin access can exploit it to compromise other users' sessions or spread malware.

Mitigation Strategies

Immediately upgrade to a patched version of 1CMS. Implement input sanitization for the article title field and ensure output encoding is applied when displaying titles. Restrict administrator access to trusted users only. Deploy Content Security Policy (CSP) headers to mitigate XSS impact.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-52307. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart