---
id: CVE-2026-52307
title: >-
  An authenticated stored cross-site scripting (XSS) vulnerability in the Column
  Management component of ClassCMS 1CMS v5.6 allows attackers to execute
  arbitrary web scripts or HTML via injecting a crafted payload into the title
  field.
summary: >-
  An authenticated stored cross-site scripting (XSS) vulnerability in the Column
  Management component of ClassCMS 1CMS v5.6 allows attackers to execute
  arbitrary web scripts or HTML via injecting a crafted payload into the title
  field.
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-09-08'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T14:17:07.820'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-52307'
references:
  - url: 'http://classcms.com'
    label: cve@mitre.org
  - url: 'https://github.com/linan-OO/CVE-2026-52307'
    label: cve@mitre.org
  - url: 'http://seclists.org/fulldisclosure/2026/Sep/31'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
  - exploit-available
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T13:28:22.364036Z'
epss: 0.00266
epssPercentile: 0.1877
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/linan-OO/CVE-2026-52307'
  checkedAt: '2026-09-21T15:29:23.835Z'
exploitAvailable: true
ingestedAt: '2026-09-08T17:06:31.888Z'
---

## Overview

An authenticated stored cross-site scripting (XSS) vulnerability in the Column Management component of ClassCMS 1CMS v5.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the title field.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
