CVE-2026-11772

DRIMO CMS is vulnerable to Reflected XSS via q parameter in searching functionality. An attacker can prepare an URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. Product is in End Of Life phase and will not receive any updates. However, deletingĀ info.php file mitigates the vulnerability,
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-06-23 14:17

Updated : 2026-06-23 15:16


NVD link : CVE-2026-11772

Mitre link : CVE-2026-11772

CVE.ORG link : CVE-2026-11772


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')