Stored Cross-Site Scripting in Feehi CMS Category Module
CVE-2026-31353
5.4MEDIUM
What is CVE-2026-31353?
An authenticated stored cross-site scripting (XSS) vulnerability exists in the Category module of Feehi CMS v2.1.1. This flaw allows attackers to inject malicious scripts through the Name parameter, potentially compromising the security of the application and its users. If successfully exploited, attackers can execute arbitrary web scripts or HTML, posing severe risks to data integrity and user privacy.
