As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-52307: Stored XSS in 1CMS v5.6
A stored cross-site scripting (XSS) vulnerability was discovered in ClassCMS 1CMS v5.6 affecting the Column Management component. An authenticated attacker can inject malicious scripts into the title field to execute arbitrary code or HTML in users' browsers.
Why it matters: Organizations running 1CMS v5.6 need to assess whether authenticated users have untrusted roles and then patch or restrict access to the Column Management component to prevent session hijacking or credential theft.
- Source published
- First seen by Cybersecurity Tracker