Medium severity5.4NVD Advisory· Published Mar 24, 2026· Updated Jun 17, 2026
CVE-2026-29840
CVE-2026-29840
Description
JiZhiCMS v2.5.6 and before contains a Stored Cross-Site Scripting (XSS) vulnerability in the release function within app/home/c/UserController.php. The application attempts to sanitize input by filtering tags but fails to recursively remove dangerous event handlers in other HTML tags (such as onerror in tags). This allows an authenticated remote attacker to inject arbitrary web script or HTML via the body parameter in a POST request to /user/release.html.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- gist.github.com/w-p-man/790f51f918499798180a8def3a6fdfb0nvdThird Party Advisory
- www.demo.com/user/release/molds/article.htmlnvdBroken Link
News mentions
0No linked articles in our index yet.