medium · CVSS v3 6.1 · CVSS v4 5.3 · EPSS 0.00215
CVE-2026-105124
This CVE affects Vincent Peugnet WCMS up to version 3.18.0, allowing unauthenticated users to inject JavaScript via the login username field
Overview
This CVE affects Vincent Peugnet WCMS up to version 3.18.0, allowing unauthenticated users to inject JavaScript via the login username field and visitor comment field. The injected scripts are rendered unescaped in the admin log viewer and comment URLs, enabling execution with administrator or editor privileges. The vulnerability can lead to cross‑site scripting that compromises the CMS interface.
Description
W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. Attackers can submit failed logins rendered unescaped in the adminlog.php log viewer, or comment URLs echoed into href attributes in editrightbar.php, executing script with administrator or editor privileges.
Impact
Confidentiality: attackers can read sensitive logs and comment data. Integrity: malicious scripts can alter the admin interface or inject further payloads. Availability: not directly affected. Administrators and editors of the CMS are the primary defenders impacted.
Remediation
Apply the official patch to upgrade WCMS to version 3.18.1 or later. Ensure all user-supplied input is properly sanitized and output is escaped, especially in adminlog.php and editrightbar.php. Implement a Content Security Policy that restricts inline scripts and disallows execution of untrusted code.
Risk context
The CVE has a medium CVSS v3 score of 6.1 and a very low EPSS of 0.00215, indicating a modest severity but low likelihood of widespread exploitation. Defenders should still prioritize patching to mitigate potential XSS attacks.
Affected products
- Vincent Peugnet WCMS
Scores
- Severity
- medium
- CVSS v2
- 6.4
- CVSS v3
- 6.1
- CVSS v4
- 5.3
- EPSS
- 0.00215