Stored Cross-Site Scripting in Feehi CMS Category Module
CVE-2026-31353

5.4MEDIUM

Key Information:

Vendor

Feehi

Status
Vendor
CVE Published:
6 April 2026

What is CVE-2026-31353?

An authenticated stored cross-site scripting (XSS) vulnerability exists in the Category module of Feehi CMS v2.1.1. This flaw allows attackers to inject malicious scripts through the Name parameter, potentially compromising the security of the application and its users. If successfully exploited, attackers can execute arbitrary web scripts or HTML, posing severe risks to data integrity and user privacy.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.