Stored Cross-Site Scripting Vulnerability in Feehi CMS
CVE-2026-31313

5.4MEDIUM

Key Information:

Vendor

Feehi

Status
Vendor
CVE Published:
6 April 2026

What is CVE-2026-31313?

Feehi CMS v2.1.1 is affected by an authenticated stored cross-site scripting vulnerability in its creation and editing module. This flaw allows attackers to inject malicious scripts or HTML into the Content field, potentially leading to arbitrary code execution in the user's browser. When exploited, this vulnerability can compromise user data and the overall integrity of the application.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.