Exponent CMS 2.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Title and Text Block parameters in the text editing endpoint. Attackers can inject iframe payloads with embedded SVG onload events to execute arbitrary JavaScript, and the application also exposes database credentials in responses and lacks brute-force protection on authentication endpoints.
Metrics
Affected Vendors & Products
References
History
Sun, 10 May 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exponent CMS 2.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Title and Text Block parameters in the text editing endpoint. Attackers can inject iframe payloads with embedded SVG onload events to execute arbitrary JavaScript, and the application also exposes database credentials in responses and lacks brute-force protection on authentication endpoints. | |
| Title | Exponent CMS 2.6 Multiple Vulnerabilities Stored XSS Authentication | |
| First Time appeared |
Exponentcms
Exponentcms exponent Cms |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:exponentcms:exponent_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Exponentcms
Exponentcms exponent Cms |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-10T12:43:51.934Z
Reserved: 2026-02-01T11:24:18.717Z
Link: CVE-2021-47931
No data.
Status : Received
Published: 2026-05-10T13:16:29.293
Modified: 2026-05-10T13:16:29.293
Link: CVE-2021-47931
No data.
OpenCVE Enrichment
Updated: 2026-05-10T15:15:14Z