PatchSiren

ClassCMS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ClassCMS CVE published 2026-09-08

CVE-2026-52307

An authenticated stored cross-site scripting (XSS) vulnerability exists in ClassCMS 1CMS v5.6, specifically in the Column Management component. This allows attackers to inject crafted payloads into the title field, potentially leading to arbitrary web script or HTML execution. The vulnerability has a CVSS score of 5.4 and is classified as MEDIUM severity. Defenders should assess exposure and verify the ef [truncated]