Aller au contenu

Fiche vulnérabilité

CVE-2025-11306 : faille moyenne qianfox foxcms (CVSS 6.1)

Description

A vulnerability was found in qianfox FoxCMS up to 1.2. This affects an unknown part of the file /index.php/Search of the component Search Page. The manipulation of the argument keyword results in cross site scripting. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

En bref

Sévérité
Moyenne (CVSS 6.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
5 oct. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • qianfox foxcms

Références

Rechercher une autre vulnérabilité dans la base CVE