---
id: CVE-2020-37237
title: >-
  Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability
  that allows authenticated administrators to inject malicious scripts through
  the banner management interface
summary: >-
  Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability
  that allows authenticated administrators to inject malicious scripts through
  the banner management interface. Attackers with admin credentials can inject
  XSS pa…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-05-16'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T10:10:00.263'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-37237'
references:
  - url: 'https://compo.sr/'
    label: disclosure@vulncheck.com
  - url: 'https://compo.sr/download.htm'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/49190'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/composr-cms-persistent-cross-site-scripting-via-banners
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00239
epssPercentile: 0.13439
ingestedAt: '2026-09-29T10:31:36.286Z'
---

## Overview

Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the banner management interface. Attackers with admin credentials can inject XSS payloads in the Description field of the Add banner functionality, which execute for all website visitors when they access the home page.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
