CVE-2026-29934

A reflected cross-site scripting (XSS) vulnerability in the /admin/menus component of Lightcms v2.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via modifying the referer value in the request header.
References
Link Resource
https://github.com/eddy8/LightCMS/issues/38 Exploit Issue Tracking Mitigation
Configurations

Configuration 1 (hide)

cpe:2.3:a:lightcms_project:lightcms:2.0:*:*:*:*:*:*:*

History

02 Apr 2026, 19:37

Type Values Removed Values Added
CPE cpe:2.3:a:lightcms_project:lightcms:2.0:*:*:*:*:*:*:*
First Time Lightcms Project lightcms
Lightcms Project
CWE CWE-79
References () https://github.com/eddy8/LightCMS/issues/38 - () https://github.com/eddy8/LightCMS/issues/38 - Exploit, Issue Tracking, Mitigation

30 Mar 2026, 13:26

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de cross-site scripting (XSS) reflejada en el componente /admin/menus de Lightcms v2.0 permite a los atacantes ejecutar Javascript arbitrario en el contexto del navegador del usuario mediante la modificación del valor del referer en la cabecera de la solicitud.

26 Mar 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

26 Mar 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-26 15:16

Updated : 2026-04-02 19:37


NVD link : CVE-2026-29934

Mitre link : CVE-2026-29934

CVE.ORG link : CVE-2026-29934


JSON object : View

Products Affected

lightcms_project

  • lightcms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')