iCMS v8.0.0 contains a Cross-Site Scripting (XSS) vulnerability in the User Management component, specifically within the index.html file. This allows remote attackers to execute arbitrary web script or HTML via the regip or loginip parameters.
References
| Link | Resource |
|---|---|
| https://wang1rrr.github.io/2026/02/09/CVE-Report-iCMS-v8.0.0-XSS/ | Exploit Third Party Advisory |
Configurations
History
25 Mar 2026, 20:53
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:idreamsoft:icms:8.0.0:*:*:*:*:*:*:* | |
| First Time |
Idreamsoft icms
Idreamsoft |
|
| References | () https://wang1rrr.github.io/2026/02/09/CVE-Report-iCMS-v8.0.0-XSS/ - Exploit, Third Party Advisory |
24 Mar 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| CWE | CWE-79 |
24 Mar 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-24 15:16
Updated : 2026-03-25 20:53
NVD link : CVE-2026-30661
Mitre link : CVE-2026-30661
CVE.ORG link : CVE-2026-30661
JSON object : View
Products Affected
idreamsoft
- icms
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
