← Back to search

CVE-2026-88415

8.7 HIGHpublic exploit available

Published 2026-09-22 · Updated 2026-09-23

AI risk analysis

Summary
The flaw allows attackers to inject malicious scripts into article content, which can be executed in the context of the victim's browser, leading to potential data exfiltration or manipulation.
Exploitability
Exploitation is relatively straightforward as attackers can inject XSS payloads through the `contentDetails` field, requiring only user interaction to trigger the vulnerability.
Blast radius
If exploited, the impact could be significant, as it affects all users viewing the affected articles, potentially leading to data theft or manipulation of user experiences.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to MCMS 6.2.2 or later, as the vulnerability is patched in this version.
xsswebcontent

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

MCMS 6.1.1 through 6.2.1 is vulnerable to stored Cross-Site Scripting (XSS). The article content field `contentDetails` is excluded from the global XSS filter.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Weaknesses

CWE-79

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.