CVE-2026-13546 is a medium-severity vulnerability in Feehi CMS, affecting its REST API endpoint. The vulnerability allows for missing authentication and can be exploited remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. The CVE was published on June 29, 2026, and has a CVSS score of 5.5.
CVE-2026-13544 is a vulnerability in Feehi CMS version up to 2.1.1. The issue lies in the /api/users endpoint of the API, where improper access controls are implemented. This vulnerability allows remote attackers to manipulate the API. The exploit for this vulnerability has been published and can be used. The project maintainers were informed about the issue but have not yet responded. Due to the low CVSS [truncated]
CVE-2026-31313 is an authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1. This vulnerability allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Content field. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. Users of Feehi CMS v2.1.1, particularly those with editing privileges, s [truncated]