VYPR

NukeViet CMS

by Vinades

CVEs (1)

  • CVE-2026-49259higJul 13, 2026
    risk 0.45cvss epss

    ## Summary A stored cross-site scripting (XSS) vulnerability exists in NukeViet CMS versions 4.x through 4.5.08. A low-privileged authenticated user can store a JavaScript payload in their profile's display name fields. The payload executes in the browser of any visitor —…