VYPR
Moderate severityNVD Advisory· Published Dec 15, 2021· Updated Aug 4, 2024

CVE-2021-44116

CVE-2021-44116

Description

Anchor CMS <=0.12.7 has a stored XSS vulnerability in posts.php, allowing attackers to steal admin cookies via malicious post titles or content.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Anchor CMS <=0.12.7 has a stored XSS vulnerability in posts.php, allowing attackers to steal admin cookies via malicious post titles or content.

Vulnerability

Anchor CMS versions 0.12.7 and earlier contain a stored Cross-Site Scripting (XSS) vulnerability in the /theme/posts.php file [1][3]. The application does not sanitize or filter user input when creating or editing posts via the posts column. Attackers can embed malicious JavaScript code into the post title or content fields, which is then stored and executed in the browsers of administrators who view the affected posts [1][3].

Exploitation

An attacker must have a registered user account with permission to create or edit posts (or be able to trick an admin into submitting malicious content). To exploit the vulnerability, the attacker creates a new post and inserts a crafted XSS payload (e.g., a ` tag) in the title or content field [3]. When an authenticated administrator views the post (e.g., in the admin panel or front-end page that renders posts.php`), the stored payload executes in the admin's browser session [1][3].

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim administrator's session. The primary impact is cookie theft: the attacker can steal the administrator's session cookie and then impersonate that user, gaining access to the admin panel [1]. This can lead to full site compromise, including the ability to modify content, create new admin accounts, or inject further malicious code [1].

Mitigation

The Anchor CMS project is no longer maintained [2]; no patched version has been released. The vendor advises users to consider alternative platforms and not rely on Anchor CMS for production use [2]. As no fix exists, users must migrate to a different, actively maintained CMS. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
anchorcms/anchor-cmsPackagist
<= 0.12.7

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.