---
id: CVE-2025-11306
title: A vulnerability was found in qianfox FoxCMS up to 1.2
summary: >-
  A vulnerability was found in qianfox FoxCMS up to 1.2. This affects an unknown
  part of the file /index.php/Search of the component Search Page. The
  manipulation of the argument keyword results in cross site scripting. The
  attack can be e…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: qianfox
product: foxcms
affected:
  - foxcms <= 1.2
published: '2025-10-05'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11306'
references:
  - url: >-
      https://github.com/coolcj-stack/FoxCMS-V1.2-is-vulnerable-to-cross-site-scripting-attacks.-There-is-an-XSS-vulnerability
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.327187'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.327187'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.661874'
    label: cna@vuldb.com
  - url: >-
      https://github.com/coolcj-stack/FoxCMS-V1.2-is-vulnerable-to-cross-site-scripting-attacks.-There-is-an-XSS-vulnerability
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00343
epssPercentile: 0.25769
ingestedAt: '2026-10-09T12:53:28.730Z'
---

## Overview

A vulnerability was found in qianfox FoxCMS up to 1.2. This affects an unknown part of the file /index.php/Search of the component Search Page. The manipulation of the argument keyword results in cross site scripting. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `foxcms <= 1.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
